<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" 'JATS-journalpublishing1-3-mathml3.dtd'>
<article article-type="research-article" dtd-version="1.3" xml:lang="EN" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Front. Phys.</journal-id>
<journal-title-group>
<journal-title>Frontiers in Physics</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Front. Phys.</abbrev-journal-title>
</journal-title-group>
<issn pub-type="epub">2296-424X</issn>
<publisher>
<publisher-name>Frontiers Media S.A.</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">1647836</article-id>
<article-id pub-id-type="doi">10.3389/fphy.2025.1647836</article-id>
<article-version article-version-type="Version of Record" vocab="NISO-RP-8-2008"/>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Original Research</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Efficient and secure authentication scheme with user anonymity based on cloud computing in 6G</article-title>
<alt-title alt-title-type="left-running-head">Ying and Jiang</alt-title>
<alt-title alt-title-type="right-running-head">
<ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3389/fphy.2025.1647836">10.3389/fphy.2025.1647836</ext-link>
</alt-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<name>
<surname>Ying</surname>
<given-names>Songpeng</given-names>
</name>
<xref ref-type="aff" rid="aff1">
<sup>1</sup>
</xref>
<xref ref-type="corresp" rid="c001">&#x2a;</xref>
<uri xlink:href="https://loop.frontiersin.org/people/3101904"/>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="conceptualization" vocab-term-identifier="https://credit.niso.org/contributor-roles/conceptualization/">Conceptualization</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Formal analysis" vocab-term-identifier="https://credit.niso.org/contributor-roles/formal-analysis/">Formal analysis</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="investigation" vocab-term-identifier="https://credit.niso.org/contributor-roles/investigation/">Investigation</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Project administration" vocab-term-identifier="https://credit.niso.org/contributor-roles/project-administration/">Project administration</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="resources" vocab-term-identifier="https://credit.niso.org/contributor-roles/resources/">Resources</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="validation" vocab-term-identifier="https://credit.niso.org/contributor-roles/validation/">Validation</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="visualization" vocab-term-identifier="https://credit.niso.org/contributor-roles/visualization/">Visualization</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Writing &#x2013; original draft" vocab-term-identifier="https://credit.niso.org/contributor-roles/writing-original-draft/">Writing &#x2013; original draft</role>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Jiang</surname>
<given-names>Zhilin</given-names>
</name>
<xref ref-type="aff" rid="aff2">
<sup>2</sup>
</xref>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Data curation" vocab-term-identifier="https://credit.niso.org/contributor-roles/data-curation/">Data curation</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="methodology" vocab-term-identifier="https://credit.niso.org/contributor-roles/methodology/">Methodology</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="software" vocab-term-identifier="https://credit.niso.org/contributor-roles/software/">Software</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="supervision" vocab-term-identifier="https://credit.niso.org/contributor-roles/supervision/">Supervision</role>
<role vocab="credit" vocab-identifier="https://credit.niso.org/" vocab-term="Writing &#x2013; review &#x26; editing" vocab-term-identifier="https://credit.niso.org/contributor-roles/writing-review-editing/">Writing &#x2013; review &#x26; editing</role>
</contrib>
</contrib-group>
<aff id="aff1">
<label>1</label>
<institution>School of Telecommunications Engineering, Xidian University</institution>, <city>Xi&#x2019;an</city>, <country country="CN">China</country>
</aff>
<aff id="aff2">
<label>2</label>
<institution>Luoyang Institute of Science and Technology Library</institution>, <city>Luoyang</city>, <country country="CN">China</country>
</aff>
<author-notes>
<corresp id="c001">
<label>&#x2a;</label>Correspondence: Songpeng Ying, <email xlink:href="24012100044@stu.xidian.edu.cn">24012100044@stu.xidian.edu.cn</email>
</corresp>
</author-notes>
<pub-date publication-format="electronic" date-type="pub" iso-8601-date="2025-11-26">
<day>26</day>
<month>11</month>
<year>2025</year>
</pub-date>
<pub-date publication-format="electronic" date-type="collection">
<year>2025</year>
</pub-date>
<volume>13</volume>
<elocation-id>1647836</elocation-id>
<history>
<date date-type="received">
<day>16</day>
<month>06</month>
<year>2025</year>
</date>
<date date-type="rev-recd">
<day>09</day>
<month>10</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>28</day>
<month>10</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>Copyright &#xa9; 2025 Ying and Jiang.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Ying and Jiang</copyright-holder>
<license>
<ali:license_ref start_date="2025-11-26">https://creativecommons.org/licenses/by/4.0/</ali:license_ref>
<license-p>This is an open-access article distributed under the terms of the <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution License (CC BY)</ext-link>. The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.</license-p>
</license>
</permissions>
<abstract>
<p>With the rapid development of 6G and the widespread adoption of cloud computing technologies, security issues in distributed cloud computing systems have become increasingly critical. Ensuring user anonymity, legitimate device access, communication security, and efficient authentication has emerged as an urgent challenge. To address these issues, this paper proposes an anonymous, secure, and efficient authentication scheme for 6G cloud computing. The scheme supports both user authentication and device access authentication by integrating Chebyshev chaotic mapping with a multi-factor authentication mechanism. It ensures secure verification of user identities and access devices and protects subsequent session keys. Furthermore, a Physical Unclonable Function (PUF) is deployed on the device side to leverage unique hardware features, providing strong identity recognition and resistance to physical attacks while improving system authentication efficiency. Performance evaluations demonstrate that the proposed scheme reduces computational overhead by an average of 30.45% and communication overhead by an average of 16.32% compared with the baseline scheme. These results confirm that the proposed scheme significantly enhances communication security between authorized users, legitimate devices, and cloud servers in 6G cloud computing environments. By combining chaotic mapping, multi-factor authentication, and PUF-based verification, the scheme achieves robust security, lightweight computation, and strong scalability suitable for next-generation distributed cloud systems.</p>
</abstract>
<kwd-group>
<kwd>6G</kwd>
<kwd>efficiency</kwd>
<kwd>authentication</kwd>
<kwd>anonymous</kwd>
<kwd>secure</kwd>
<kwd>cloud computing</kwd>
</kwd-group>
<funding-group>
<funding-statement>The author(s) declare that no financial support was received for the research and/or publication of this article.</funding-statement>
</funding-group>
<counts>
<fig-count count="5"/>
<table-count count="5"/>
<equation-count count="12"/>
<ref-count count="48"/>
<page-count count="12"/>
</counts>
<custom-meta-group>
<custom-meta>
<meta-name>section-in-acceptance</meta-name>
<meta-value>Social Physics</meta-value>
</custom-meta>
</custom-meta-group>
</article-meta>
</front>
<body>
<sec sec-type="intro" id="s1">
<label>1</label>
<title>Introduction</title>
<p>With commercialization of the fifth-generation (5G) mobile communication network, major global telecom operators and technology companies are now shifting their research and development focus to the sixth-generation (6G) network. 6G is envisioned not only as a faster, lower-latency and more widely covered communication platform, but also as a transformative infrastructure that enables the true interconnection of everything. This integration is expected to trigger profound societal transformation and technological innovation, laying the foundation for a new era of intelligent infrastructure.</p>
<p>In this transformative process, cloud computing&#x2014;serving as a core supporting technology&#x2014;will demonstrate greater capabilities and wider application scenarios in the 6G. Benefiting from 6G&#x2019;s high data transmission rates, ultra-low latency, high reliability and edge-distributed architecture, cloud computing will overcome the limitations of traditional networks in bandwidth, delay and resource allocation. This will extend computing and service capabilities toward the network edge, enabling faster data processing, lower service response times and more intelligent decision-making [<xref ref-type="bibr" rid="B1">1</xref>].</p>
<p>In the realm of smart cities, the integration of cloud computing and 6G can support real-time acquisition and analysis of massive data from high-definition video surveillance, intelligent traffic control systems and public safety management, enabling intelligent scheduling of urban resources and rapid response to events. In the industrial internet, cloud platforms can monitor the operational status of factory equipment and production line data in real time, enabling predictive maintenance and significantly improving production efficiency and equipment utilization [<xref ref-type="bibr" rid="B2">2</xref>]. In autonomous driving scenarios, vehicles can maintain high-speed communication with the cloud via 6G networks, uploading sensor data for real-time cloud-based processing to enhance perception and decision-making capabilities. In telemedicine, doctors can use ultra-high-definition imaging and real-time interactive systems to guide surgeries or monitor the health of remote patients, greatly alleviating the imbalance of medical resource distribution. For immersive experiences such as Virtual Reality (VR)/Augmented Reality (AR) and holographic communication, complex graphics rendering and scene generation can be handled in the cloud and transmitted back to the user terminal via the 6G network, ensuring smooth and immersive user experiences [<xref ref-type="bibr" rid="B3">3</xref>].</p>
<p>However, as cloud computing continues to evolve, ensuring user privacy and data security within cloud environments has become an urgent issue. In 6G, the scale of user and device access is expected to reach unprecedented levels. Traditional authentication mechanisms may face significant challenges, including excessive latency and computational overhead, in handling such large-scale user access and device authentication. This is particularly true in cloud computing environments, where authentication processes may involve extensive data processing and transmission, placing greater demands on authentication efficiency [<xref ref-type="bibr" rid="B4">4</xref>&#x2013;<xref ref-type="bibr" rid="B6">6</xref>]. Moreover, in traditional identity authentication mechanisms, users may need to disclose certain identity information during the authentication process, which poses risks of privacy leakage or exploitation by attackers. Therefore, there is a pressing need to design a cloud computing-based anonymous and secure authentication scheme that not only protects user privacy but also significantly enhances authentication efficiency.</p>
<sec id="s1-1">
<label>1.1</label>
<title>Related work</title>
<p>At present, extensive research has been conducted both domestically and internationally in the fields of authentication and key agreement, resulting in the proposal of various protocol schemes aimed at ensuring the security of authentication processes and data communications [<xref ref-type="bibr" rid="B7">7</xref>&#x2013;<xref ref-type="bibr" rid="B13">13</xref>].</p>
<p>Parai et al. [<xref ref-type="bibr" rid="B10">10</xref>] based on Gupta&#x2019;s [<xref ref-type="bibr" rid="B9">9</xref>] research, proposed an identity-based three-party authentication key negotiation protocol for resource-constrained IoT devices. They tested and estimated the execution time of the protocol on a Raspberry Pi 4 device, covering security levels from 80 bits to 256 bits. However, since the protocol is based on bilinear pairings, it still has a high computational cost. In 2023, Mookherji et al. [<xref ref-type="bibr" rid="B11">11</xref>] proposed a semi-centralized architecture and a certification and key negotiation scheme for smart healthcare systems. In this scheme, the cloud server delegates user registration functionality to fog servers, and users can complete registration by sending requests to fog servers. This scheme claims to effectively address the threat of server single-point compromise. However, fog servers are typically deployed close to the device edge layer and are considered untrusted. Compared to centralized cloud servers, fog servers have higher key management costs and challenges. Qiu et al. [<xref ref-type="bibr" rid="B14">14</xref>] addressed the imbalance between practicality and security in three-factor authentication by proposing a lightweight mobile device authentication scheme using chaotic mapping. The scheme utilizes fuzzy verifiers and honeyword techniques to resist offline password guessing attacks. In 2021, Lin et al. [<xref ref-type="bibr" rid="B15">15</xref>] introduced an authentication protocol tailored for 5G healthcare IoT systems, enabling patients to access multiple remote medical services using paired credentials. However, due to the absence of timestamps and the use of a public authentication parameter, the scheme is susceptible to Denial of Service (DoS) attacks. Additionally, storing users&#x2019; private keys in plaintext on the smart card leaves it vulnerable to card theft attacks. To address identity verification in Wireless Body Area Networks (WBAN), Alzahrani et al. [<xref ref-type="bibr" rid="B16">16</xref>] introduced a lightweight protocol that facilitates session key generation between sensor and hub nodes. Nevertheless, it lacks comprehensive mutual authentication among access points, hubs, and sensors, limiting its practical deployment. Nyangaresi et al. [<xref ref-type="bibr" rid="B17">17</xref>] proposed a cheme to secure interactions between body sensor units and administrators in WBAN scenarios, achieving forward secrecy through session key generation. Yet, the protocol fails to preserve user anonymity when the gateway node acts as an insider adversary.</p>
<p>Xie et al. [<xref ref-type="bibr" rid="B18">18</xref>] designed a scheme for patient monitoring systems using elliptic curve cryptography (ECC) and validated its security via formal analysis. However, it does not implement mutual authentication between sensor and relay nodes. Deebak et al. [<xref ref-type="bibr" rid="B19">19</xref>] designed a framework for cloud-assisted medical cyber-physical systems based on Chebyshev chaotic maps. A major weakness lies in the registration phase, where user credentials are transmitted in plaintext to the gateway, risking identity exposure. Tu et al. [<xref ref-type="bibr" rid="B20">20</xref>] also proposed EAKE-WCI, an anonymous authentication protocol for wearable healthcare devices in cloud environments. While the scheme ensures mutual authentication among users, devices, and servers, it lacks adequate password protection during login, making it vulnerable to guessing attacks. Edwards et al. [<xref ref-type="bibr" rid="B21">21</xref>] introduced a distributed authentication framework, incorporating physical tokens, biometrics, and cryptographic keys to validate user identity. Lee et al. [<xref ref-type="bibr" rid="B22">22</xref>] developed a three-factor authentication method tailored for sensor-based devices operating in IoT settings. Their approach utilizes Physical Unclonable Function (PUF) and honeypot mechanisms to mitigate threats such as ID/password guessing, brute-force, and eavesdropping attacks. Mirsaraei et al. [<xref ref-type="bibr" rid="B23">23</xref>] introduced another three-factor authentication protocol suitable for IoT applications, employing elliptic curve cryptography and smart cards for user registration and identity verification within private blockchain environments. This design is particularly effective for resource-constrained IoT devices. Ghose et al. [<xref ref-type="bibr" rid="B25">25</xref>] presented two-factor authentication protocol. Initial verification step is based on traditional credentials (username and password), while the second step leverages persistent associations between the user&#x2019;s device and an auxiliary unit. Ahmad et al. [<xref ref-type="bibr" rid="B26">26</xref>] introduced BAuth-ZKP, a multi-factor authentication protocol designed for smart city. By utilizing blockchain smart contracts, the scheme enables secure user verification without revealing personal identity information. Braeken et al. [<xref ref-type="bibr" rid="B27">27</xref>] developed a two-way multi-factor authentication and key exchange mechanism aimed at facilitating secure access to remote sensor nodes. Their approach ensures real-time data retrieval and defends against semi-trusted intermediaries, while preserving user anonymity and untraceability, and mitigating risks from session-specific data leakage. In the healthcare sector, Miao et al. [<xref ref-type="bibr" rid="B28">28</xref>] proposed a three-factor authentication protocol for medical IoT systems, leveraging blockchain to manage identity-related data and applying Chebyshev chaotic maps to enhance login and authentication robustness. Zhang et al. [<xref ref-type="bibr" rid="B29">29</xref>] presented an ECC-based three-factor scheme involving credentials, passwords, and biometrics for secure interaction among administrators, gateways, and industrial IoT devices. This protocol supports identity revocation and online updates, adapting to dynamic industrial requirements. To enhance cloud network security, Bernard et al. [<xref ref-type="bibr" rid="B30">30</xref>] designed a mutual authentication protocol utilizing visual cryptography. The approach employs confidential mappings&#x2014;specifically visual encryption and challenge-response pairs&#x2014;along with credential-based verification to counteract weaknesses in traditional cryptographic algorithms. Despite its enhanced security features, the scheme incurs significant computational cost, which limits its efficiency on resource-limited platforms.</p>
<p>PUF is an emerging cryptographic primitive known for its strong resistance to duplication. Min et al. [<xref ref-type="bibr" rid="B32">32</xref>] designed an authentication approach that integrates PUF with a dynamic identity mechanism, effectively safeguarding device identities and enhancing privacy at the hardware level. In a subsequent work, Aman et al. [<xref ref-type="bibr" rid="B33">33</xref>] developed a PUF-based mutual authentication protocol, enabling secure communication between devices and servers, as well as among devices themselves, thereby expanding its applicability. Shah et al. [<xref ref-type="bibr" rid="B34">34</xref>] presented a PUF-enabled authentication mechanism that employs challenge&#x2013;response pairs and incorporates the AES encryption algorithm to improve overall system security. Zhu et al. [<xref ref-type="bibr" rid="B35">35</xref>] introduced a PUF-driven authentication protocol specifically designed for RFID environments, addressing critical security concerns such as unclonability and traceability, while also supporting mutual authentication. In summary, current authentication schemes still have security vulnerabilities and incur high computational and communication costs [<xref ref-type="bibr" rid="B24">24</xref>&#x2013;<xref ref-type="bibr" rid="B31">31</xref>].</p>
</sec>
<sec id="s1-2">
<label>1.2</label>
<title>Contributions</title>
<p>In this paper, we propose a cloud-based anonymous and secure authentication scheme. Our approach enables mutual authentication between users and access devices, allowing them to securely establish a reliable shared session key. Communication efficiency is also considered in the proposed scheme. The main contributions of this work can be summarized as follows:</p>
<p>The security of the proposed scheme is proven under the Random Oracle Model. Additionally, security analysis demonstrates that the proposed scheme can withstand common attacks. Performance comparisons show that the proposed scheme addresses the security shortcomings of existing solutions and has lower computational and communication overhead.<list list-type="order">
<list-item>
<p>This paper proposes an anonymous, secure, and efficient authentication scheme for cloud-based in 6G. The proposed scheme employs Chebyshev chaotic mapping and PUF to construct a lightweight key agreement mechanism. Additionally, by integrating hash functions and a session key update strategy, the scheme ensures user anonymity and forward security of session data. PUF technology is incorporated on the device side, leveraging its unique hardware characteristics to provide robust identity verification and resistance to physical attacks.</p>
</list-item>
<list-item>
<p>The security of the proposed scheme is formally proven under the random oracle model. Furthermore, the security analysis demonstrates that the scheme is resilient against common types of attacks. Performance comparisons indicate that the proposed solution addresses the security weaknesses of existing schemes while maintaining low computation and communication overhead.</p>
</list-item>
</list>
</p>
</sec>
<sec id="s1-3">
<label>1.3</label>
<title>Paper organization</title>
<p>The structure of this paper is arranged as follows. <xref ref-type="sec" rid="s2">Section 2</xref> outlines the foundational concepts relevant to the proposed scheme. <xref ref-type="sec" rid="s3">Section 3</xref> details the authentication protocol in depth. <xref ref-type="sec" rid="s4">Sections 4</xref> and <xref ref-type="sec" rid="s5">5</xref> are dedicated to the security assessment and efficiency analysis of the scheme. The final section concludes the study and highlights potential avenues for future exploration.</p>
</sec>
</sec>
<sec id="s2">
<label>2</label>
<title>Preliminaries</title>
<p>This section presents the relevant background of proposed scheme, with detailed explanations provided below.</p>
<sec id="s2-1">
<label>2.1</label>
<title>System architecture</title>
<p>As shown in <xref ref-type="fig" rid="F1">Figure 1</xref>, cloud-based authentication protocol proposed in this paper consists of three main components: cloud servers, users, and access devices. These components are interconnected via a high-speed, highly reliable 6G core network, forming a secure communication architecture that supports large-scale heterogeneous device access.</p>
<fig id="F1" position="float">
<label>FIGURE 1</label>
<caption>
<p>System architecture.</p>
</caption>
<graphic xlink:href="fphy-13-1647836-g001.tif">
<alt-text content-type="machine-generated">Diagram illustrating a 6G core network connecting factory and home sensors via cloud servers. Arrows indicate data flow from sensors to the cloud and network, involving figures representing technology and people.</alt-text>
</graphic>
</fig>
<p>Cloud Servers: Serving as the central management entities, cloud servers are responsible for identity authentication, key management, secure storage, and data processing.</p>
<p>Users: It refers to individuals or organizations utilizing the system services, including system administrators, household users, and industrial control personnel. Users initiate authentication requests via terminals to access cloud resources or remotely control access devices.</p>
<p>Access Devices: These are intelligent terminal devices deployed in various application environments, equipped with communication, control, and response capabilities. Beyond simply connecting to the cloud platform, they can execute task instructions, report status information, and trigger predefined actions. Depending on the application scenario, access devices include the following:<list list-type="bullet">
<list-item>
<p>Industrial control terminals, actuators, and robots in factory settings, enabling automated operations and status feedback;</p>
</list-item>
<list-item>
<p>Smart cameras, locks, and lighting systems in home environments, allowing remote control and environmental regulation;</p>
</list-item>
<list-item>
<p>Embedded intelligent devices in fields such as healthcare, transportation, and energy, capable of edge-level sensing, state synchronization, and policy-based responses.</p>
</list-item>
</list>
</p>
<p>Access devices engage in mutual authentication with both users and cloud servers via the proposed protocol, ensuring that all communications occur in a trusted and secure environment, thereby preventing unauthorized access and data leakage.</p>
<p>Leveraging the high bandwidth and low latency characteristics of 6G core network, proposed system achieves strong security guarantees while meeting real-time performance requirements and supporting massive connectivity.</p>
</sec>
<sec id="s2-2">
<label>2.2</label>
<title>Chebyshev chaotic mapping</title>
<p>Given an integer <inline-formula id="inf1">
<mml:math id="m1">
<mml:mrow>
<mml:mi>n</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> and a variable <inline-formula id="inf2">
<mml:math id="m2">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, where <inline-formula id="inf3">
<mml:math id="m3">
<mml:mrow>
<mml:mi>x</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf4">
<mml:math id="m4">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>n</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> can be defined as:<disp-formula id="e1">
<mml:math id="m5">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>n</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>cos</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mo>&#xb7;</mml:mo>
<mml:mo>&#x2061;</mml:mo>
<mml:mi>arccos</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
<label>(1)</label>
</disp-formula>
</p>
<p>From <xref ref-type="disp-formula" rid="e1">Equation 1</xref>, the recursive formula for Chebyshev polynomials is derived as <xref ref-type="disp-formula" rid="e2">Equation 2</xref> [<xref ref-type="bibr" rid="B36">36</xref>&#x2013;<xref ref-type="bibr" rid="B38">38</xref>]:<disp-formula id="e2">
<mml:math id="m6">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>n</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mfenced open="{" close="" separators="&#x7c;">
<mml:mrow>
<mml:mtable columnalign="left">
<mml:mtr>
<mml:mtd>
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
</mml:mrow>
</mml:mtd>
<mml:mtd>
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>0</mml:mn>
</mml:mrow>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd>
<mml:mrow>
<mml:mi>x</mml:mi>
<mml:mo>,</mml:mo>
</mml:mrow>
</mml:mtd>
<mml:mtd>
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mtd>
</mml:mtr>
<mml:mtr>
<mml:mtd>
<mml:mrow>
<mml:mn>2</mml:mn>
<mml:mi>x</mml:mi>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
</mml:mrow>
</mml:mtd>
<mml:mtd>
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mo>&#x2265;</mml:mo>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:mtd>
</mml:mtr>
</mml:mtable>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
<label>(2)</label>
</disp-formula>
</p>
<p>According to the above formulas, Chebyshev polynomials satisfy the semi-group property. That is, for any two positive integers <inline-formula id="inf5">
<mml:math id="m7">
<mml:mrow>
<mml:mi>s</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf6">
<mml:math id="m8">
<mml:mrow>
<mml:mi>u</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf7">
<mml:math id="m9">
<mml:mrow>
<mml:mi>x</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, <xref ref-type="disp-formula" rid="e3">Equation 3</xref> holds:<disp-formula id="e3">
<mml:math id="m10">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>s</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>u</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>u</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>u</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>s</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
<label>(3)</label>
</disp-formula>
</p>
<p>The semigroup property [<xref ref-type="bibr" rid="B43">43</xref>]: For <inline-formula id="inf8">
<mml:math id="m11">
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mo>&#x2265;</mml:mo>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf9">
<mml:math id="m12">
<mml:mrow>
<mml:mi>x</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:mi>&#x221e;</mml:mi>
<mml:mo>,</mml:mo>
<mml:mo>&#x2b;</mml:mo>
<mml:mi>&#x221e;</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, the enhanced Chebyshev polynomial is defined as <xref ref-type="disp-formula" rid="e4">Equation 4</xref>:<disp-formula id="e4">
<mml:math id="m13">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>n</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mn>2</mml:mn>
<mml:mi>x</mml:mi>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>n</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2004;</mml:mo>
<mml:mi>mod</mml:mi>
<mml:mtext>&#x2009;</mml:mtext>
<mml:mspace width="0.17em"/>
<mml:mi>p</mml:mi>
</mml:mrow>
</mml:math>
<label>(4)</label>
</disp-formula>where <inline-formula id="inf10">
<mml:math id="m14">
<mml:mrow>
<mml:mi>p</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is a large prime number. Based on this definition, the enhanced Chebyshev polynomial still satisfies the semi-group property, expressed as <xref ref-type="disp-formula" rid="e5">Equation 5</xref>:<disp-formula id="e5">
<mml:math id="m15">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>s</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>u</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2261;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>u</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>u</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>s</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2004;</mml:mo>
<mml:mi>mod</mml:mi>
<mml:mtext>&#x2009;</mml:mtext>
<mml:mspace width="0.17em"/>
<mml:mi>p</mml:mi>
</mml:mrow>
</mml:math>
<label>(5)</label>
</disp-formula>
</p>
<p>Chebyshev Polynomial-Based Diffie-Hellman Problem (<inline-formula id="inf11">
<mml:math id="m16">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>M</mml:mi>
<mml:mi>D</mml:mi>
<mml:mi>L</mml:mi>
<mml:mi>P</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>): For any positive integers <inline-formula id="inf12">
<mml:math id="m17">
<mml:mrow>
<mml:mi>s</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf13">
<mml:math id="m18">
<mml:mrow>
<mml:mi>u</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, and any <inline-formula id="inf14">
<mml:math id="m19">
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:mi>&#x221e;</mml:mi>
<mml:mo>,</mml:mo>
<mml:mo>&#x2b;</mml:mo>
<mml:mi>&#x221e;</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, given <inline-formula id="inf15">
<mml:math id="m20">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>s</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>c</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf16">
<mml:math id="m21">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>u</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>c</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, it is computationally hard to derive <inline-formula id="inf17">
<mml:math id="m22">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>u</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>c</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>s</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>u</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>c</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2004;</mml:mo>
<mml:mi>mod</mml:mi>
<mml:mtext>&#x2009;</mml:mtext>
<mml:mi>p</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, due to the semi-group property of Chebyshev polynomials modulo a large prime <inline-formula id="inf18">
<mml:math id="m23">
<mml:mrow>
<mml:mi>p</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> [<xref ref-type="bibr" rid="B39">39</xref>&#x2013;<xref ref-type="bibr" rid="B41">41</xref>].</p>
</sec>
<sec id="s2-3">
<label>2.3</label>
<title>Physical unclonable function</title>
<p>Physical Unclonable Function (PUF) is cryptographic primitives embedded as circuit modules within chips, serving as hardware security mechanisms. They exploit random physical variations introduced during manufacturing, which are uncontrollable and unique to each device. This inherent randomness ensures that producing two identical PUF-enabled devices is practically impossible. Consequently, PUF is increasingly utilized in information security, particularly for lightweight device authentication and as novel factors in multi-factor authentication protocols.</p>
<p>PUF operates using a challenge-response mechanism: input signals, termed challenges, are processed by the PUF to generate unique responses, collectively forming Challenge-Response Pairs (CRPs). In a typical authentication setup, the PUF circuit is embedded within the authentication server. During registration, the server receives challenges from authenticating devices, processes them via its PUF module, and generates corresponding responses, which can be stored as CRPs in a database for future verification. Due to the uniqueness and tamper-resistance of PUF, these responses remain consistent and unforgeable. An ideal PUF satisfies three critical properties:<list list-type="order">
<list-item>
<p>Uniqueness: Identical challenges input to the same PUF always yield identical responses, while different PUFs produce different responses even when presented with identical challenges.</p>
</list-item>
<list-item>
<p>One-wayness: Given a known response, it is computationally infeasible to derive the original challenge that produced it.</p>
</list-item>
<list-item>
<p>Tamper-resistance: Physical attacks damage the PUF&#x2019;s physical structure, thereby disrupting its challenge-response behavior and rendering its authentication function unusable.</p>
</list-item>
</list>
</p>
<p>These characteristics make PUF particularly suitable for secure, hardware-level identity verification in resource-constrained environments.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Proposed scheme</title>
<p>This section provides a comprehensive explanation of the proposed scheme, which is built upon an enhanced Chebyshev chaotic map. <xref ref-type="table" rid="T1">Table 1</xref> outlines the symbols and cryptographic operations utilized throughout the scheme.</p>
<table-wrap id="T1" position="float">
<label>TABLE 1</label>
<caption>
<p>Symbols used in the proposed scheme.</p>
</caption>
<table>
<thead valign="top">
<tr>
<th align="center">Symbol</th>
<th align="center">Description</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td align="center">
<inline-formula id="inf19">
<mml:math id="m24">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">Cloud server</td>
</tr>
<tr>
<td align="center">
<inline-formula id="inf20">
<mml:math id="m25">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">User</td>
</tr>
<tr>
<td align="center">
<inline-formula id="inf21">
<mml:math id="m26">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">Access device</td>
</tr>
<tr>
<td align="center">
<inline-formula id="inf22">
<mml:math id="m27">
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">Identity of user <inline-formula id="inf23">
<mml:math id="m28">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
</tr>
<tr>
<td align="center">
<inline-formula id="inf24">
<mml:math id="m29">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">Password of user <inline-formula id="inf25">
<mml:math id="m30">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
</tr>
<tr>
<td align="center">
<inline-formula id="inf26">
<mml:math id="m31">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mi>U</mml:mi>
<mml:mi>F</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">Physical unclonable function</td>
</tr>
<tr>
<td align="center">
<inline-formula id="inf27">
<mml:math id="m32">
<mml:mrow>
<mml:mi>G</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">Biometric generation function</td>
</tr>
<tr>
<td align="center">
<inline-formula id="inf28">
<mml:math id="m33">
<mml:mrow>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">One-way hash function</td>
</tr>
<tr>
<td align="center">
<inline-formula id="inf29">
<mml:math id="m34">
<mml:mrow>
<mml:msub>
<mml:mi>E</mml:mi>
<mml:mi>k</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">Symmetric encryption with key <inline-formula id="inf30">
<mml:math id="m35">
<mml:mrow>
<mml:mi>k</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
</tr>
<tr>
<td align="center">
<inline-formula id="inf31">
<mml:math id="m36">
<mml:mrow>
<mml:mi>R</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>p</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">Biometric replication function</td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s3-1">
<label>3.1</label>
<title>System initialization</title>
<p>Cloud server <inline-formula id="inf32">
<mml:math id="m37">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> selects a large prime number <inline-formula id="inf33">
<mml:math id="m38">
<mml:mrow>
<mml:mi>p</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, generates a random number <inline-formula id="inf34">
<mml:math id="m39">
<mml:mrow>
<mml:mi>k</mml:mi>
<mml:mo>&#x2208;</mml:mo>
<mml:msubsup>
<mml:mi mathvariant="double-struck">Z</mml:mi>
<mml:mi>p</mml:mi>
<mml:mo>&#x2a;</mml:mo>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula> and hash function <inline-formula id="inf35">
<mml:math id="m40">
<mml:mrow>
<mml:mi>h</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>. Then, <inline-formula id="inf36">
<mml:math id="m41">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> computes <inline-formula id="inf37">
<mml:math id="m42">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>k</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, and publicly discloses the parameters <inline-formula id="inf38">
<mml:math id="m43">
<mml:mrow>
<mml:mfenced open="{" close="}" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>k</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:mi>x</mml:mi>
<mml:mo>,</mml:mo>
<mml:mi>h</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:math>
</inline-formula>, while keeping <inline-formula id="inf39">
<mml:math id="m44">
<mml:mrow>
<mml:mi>k</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> as a long-term private key securely stored. <xref ref-type="fig" rid="F2">Figure 2</xref> is flowchart for proposed scheme.</p>
<fig id="F2" position="float">
<label>FIGURE 2</label>
<caption>
<p>Flowchart for proposed scheme.</p>
</caption>
<graphic xlink:href="fphy-13-1647836-g002.tif">
<alt-text content-type="machine-generated">Flowchart illustrating an authentication process. It starts with initialization followed by user or device registration. The flow asks if the user logs in. If yes, it proceeds to check if the cloud server authenticates the user's identity. If authenticated, it checks if access authenticates the cloud server's identity. Finally, it verifies if the user authenticates the cloud server's identity. If all are positive, the process is complete. Negative responses at any step result in ending the session.</alt-text>
</graphic>
</fig>
</sec>
<sec id="s3-2">
<label>3.2</label>
<title>Registration</title>
<sec id="s3-2-1">
<label>3.2.1</label>
<title>Access device registration</title>
<p>
<inline-formula id="inf40">
<mml:math id="m45">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> sends its identity <inline-formula id="inf41">
<mml:math id="m46">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> to Cloud server. The registration process is as follows:</p>
<p>
<italic>Step 1:</italic> Access device <inline-formula id="inf42">
<mml:math id="m47">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> choose its identity <inline-formula id="inf43">
<mml:math id="m48">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, selects a challenge value <inline-formula id="inf44">
<mml:math id="m49">
<mml:mrow>
<mml:msub>
<mml:mi>N</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, computes <inline-formula id="inf45">
<mml:math id="m50">
<mml:mrow>
<mml:mi>F</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>U</mml:mi>
<mml:mi>F</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf46">
<mml:math id="m51">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>U</mml:mi>
<mml:mi>F</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>N</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, and sends the registration information <inline-formula id="inf47">
<mml:math id="m52">
<mml:mrow>
<mml:mfenced open="{" close="}" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>F</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:math>
</inline-formula> to <inline-formula id="inf48">
<mml:math id="m53">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
<p>
<italic>Step 2:</italic> Upon receiving <inline-formula id="inf49">
<mml:math id="m54">
<mml:mrow>
<mml:mfenced open="{" close="}" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>F</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf50">
<mml:math id="m55">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> first checks whether <inline-formula id="inf51">
<mml:math id="m56">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is already registered. If it is not registered, cloud server computes <inline-formula id="inf52">
<mml:math id="m57">
<mml:mrow>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>k</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf53">
<mml:math id="m58">
<mml:mrow>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x2295;</mml:mo>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, then sends <inline-formula id="inf54">
<mml:math id="m59">
<mml:mrow>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> to <inline-formula id="inf55">
<mml:math id="m60">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and stores <inline-formula id="inf56">
<mml:math id="m61">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf57">
<mml:math id="m62">
<mml:mrow>
<mml:mi>F</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf58">
<mml:math id="m63">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> in cloud server database.</p>
<p>
<italic>Step 3:</italic> The access device <inline-formula id="inf59">
<mml:math id="m64">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> receives the message, saves <inline-formula id="inf60">
<mml:math id="m65">
<mml:mrow>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and the challenge value <inline-formula id="inf61">
<mml:math id="m66">
<mml:mrow>
<mml:msub>
<mml:mi>N</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
</sec>
<sec id="s3-2-2">
<label>3.2.2</label>
<title>User registration</title>
<p>
<italic>Step 1:</italic> <inline-formula id="inf62">
<mml:math id="m67">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> selects identity <inline-formula id="inf63">
<mml:math id="m68">
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf64">
<mml:math id="m69">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, then selects a random number <inline-formula id="inf65">
<mml:math id="m70">
<mml:mrow>
<mml:msub>
<mml:mi>k</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, computes <inline-formula id="inf66">
<mml:math id="m71">
<mml:mrow>
<mml:mi>R</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>k</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, and sends <inline-formula id="inf67">
<mml:math id="m72">
<mml:mrow>
<mml:mfenced open="{" close="}" separators="&#x7c;">
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>R</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:math>
</inline-formula> to cloud server.</p>
<p>
<italic>Step 2:</italic> When <inline-formula id="inf68">
<mml:math id="m73">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> receives the message, it first checks if the user&#x2019;s <inline-formula id="inf69">
<mml:math id="m74">
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> already exists. If it already exists, meaning user is already registered, <inline-formula id="inf70">
<mml:math id="m75">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> end the session. If there is no duplication, cloud server proceeds to the next step. The cloud server generates an anonymous identity <inline-formula id="inf71">
<mml:math id="m76">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>E</mml:mi>
<mml:mi>k</mml:mi>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x2016;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mn>0</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, where <inline-formula id="inf72">
<mml:math id="m77">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mn>0</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is the current timestamp, computes <inline-formula id="inf73">
<mml:math id="m78">
<mml:mrow>
<mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>k</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf74">
<mml:math id="m79">
<mml:mrow>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>R</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>k</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf75">
<mml:math id="m80">
<mml:mrow>
<mml:msub>
<mml:mi>Z</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>R</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, stores <inline-formula id="inf76">
<mml:math id="m81">
<mml:mrow>
<mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf77">
<mml:math id="m82">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf78">
<mml:math id="m83">
<mml:mrow>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf79">
<mml:math id="m84">
<mml:mrow>
<mml:msub>
<mml:mi>Z</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> in SC. Then <inline-formula id="inf80">
<mml:math id="m85">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> sends it to <inline-formula id="inf81">
<mml:math id="m86">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
<p>
<italic>Step 3:</italic> Upon receiving SC, <inline-formula id="inf82">
<mml:math id="m87">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> inputs their biometric features <inline-formula id="inf83">
<mml:math id="m88">
<mml:mrow>
<mml:msub>
<mml:mi>B</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, calculates <inline-formula id="inf84">
<mml:math id="m89">
<mml:mrow>
<mml:mi>G</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>B</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3b4;</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3c3;</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, then computes <inline-formula id="inf85">
<mml:math id="m90">
<mml:mrow>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>k</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x2295;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3c3;</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, and generates a challenge <inline-formula id="inf86">
<mml:math id="m91">
<mml:mrow>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, calculating <inline-formula id="inf87">
<mml:math id="m92">
<mml:mrow>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>U</mml:mi>
<mml:mi>F</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>. The user then computes <inline-formula id="inf88">
<mml:math id="m93">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x2295;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c3;</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf89">
<mml:math id="m94">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x2295;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>. Finally, the user stores <inline-formula id="inf90">
<mml:math id="m95">
<mml:mrow>
<mml:mfenced open="{" close="}" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3c4;</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>Z</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:math>
</inline-formula> in their smart card SC, and securely keeps the smart card.</p>
</sec>
</sec>
<sec id="s3-3">
<label>3.3</label>
<title>Login and authentication</title>
<p>At this phase, user and the access device complete authentication and key agreement through the cloud server. The process is illustrated in <xref ref-type="fig" rid="F3">Figure 3</xref>.</p>
<fig id="F3" position="float">
<label>FIGURE 3</label>
<caption>
<p>Login and authentication.</p>
</caption>
<graphic xlink:href="fphy-13-1647836-g003.tif">
<alt-text content-type="machine-generated">A flowchart illustrating a multi-step security protocol involving a user, a cloud server, and an access device. The protocol consists of six steps, each detailing specific operations like generating keys, checking freshness, and hashing. Processes involve mathematical functions and encryption techniques, exchanging multiple messages (Msg1 to Msg5) between entities, and using random numbers and parameters (e.g., \(D_j\), \(P_j\), \(R_j\)). Each step outlines interactions in sequence, with operations such as \(Rep\), \(PUF\), \(h\), and \(\oplus\).</alt-text>
</graphic>
</fig>
<p>
<italic>Step 1:</italic> The user <inline-formula id="inf91">
<mml:math id="m96">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> inserts the smart card <inline-formula id="inf92">
<mml:math id="m97">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>,</mml:mo>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> inputs their <inline-formula id="inf93">
<mml:math id="m98">
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, login password <inline-formula id="inf94">
<mml:math id="m99">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and provides biometric information <inline-formula id="inf95">
<mml:math id="m100">
<mml:mrow>
<mml:msubsup>
<mml:mi>B</mml:mi>
<mml:mi>i</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula>. Then, calculate <inline-formula id="inf96">
<mml:math id="m101">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c3;</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>R</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>p</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msubsup>
<mml:mi>B</mml:mi>
<mml:mi>i</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3b4;</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, compute <inline-formula id="inf97">
<mml:math id="m102">
<mml:mrow>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>U</mml:mi>
<mml:mi>F</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf98">
<mml:math id="m103">
<mml:mrow>
<mml:msub>
<mml:mi>k</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x2295;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3c3;</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>. Next, calculate <inline-formula id="inf99">
<mml:math id="m104">
<mml:mrow>
<mml:mi>R</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>&#x3b8;</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>k</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x2295;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>&#x3c3;</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf100">
<mml:math id="m105">
<mml:mrow>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x2295;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>. Then, calculate <inline-formula id="inf101">
<mml:math id="m106">
<mml:mrow>
<mml:msubsup>
<mml:mi>Z</mml:mi>
<mml:mi>i</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <inline-formula id="inf102">
<mml:math id="m107">
<mml:mrow>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>R</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, and check if <inline-formula id="inf103">
<mml:math id="m108">
<mml:mrow>
<mml:msubsup>
<mml:mi>Z</mml:mi>
<mml:mi>i</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>Z</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> Afterward, <inline-formula id="inf104">
<mml:math id="m109">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> generates two random numbers <inline-formula id="inf105">
<mml:math id="m110">
<mml:mrow>
<mml:msub>
<mml:mi>r</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf106">
<mml:math id="m111">
<mml:mrow>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> Calculate <inline-formula id="inf107">
<mml:math id="m112">
<mml:mrow>
<mml:msub>
<mml:mi>E</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:msub>
<mml:mi>r</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:msub>
<mml:mi>r</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mi>u</mml:mi>
<mml:msub>
<mml:mi>b</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2295;</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf108">
<mml:math id="m113">
<mml:mrow>
<mml:msub>
<mml:mi>G</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>E</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mn>1</mml:mn>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> User <inline-formula id="inf109">
<mml:math id="m114">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> sends the message <inline-formula id="inf110">
<mml:math id="m115">
<mml:mrow>
<mml:mfenced open="{" close="}" separators="&#x7c;">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>E</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>G</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mn>1</mml:mn>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>F</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:math>
</inline-formula> to cloud server <inline-formula id="inf111">
<mml:math id="m116">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
<p>
<italic>Step 2:</italic> <inline-formula id="inf112">
<mml:math id="m117">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> receives the login request from <inline-formula id="inf113">
<mml:math id="m118">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf114">
<mml:math id="m119">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> first checks <inline-formula id="inf115">
<mml:math id="m120">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mn>1</mml:mn>
</mml:msub>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> Then, <inline-formula id="inf116">
<mml:math id="m121">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> computes <inline-formula id="inf117">
<mml:math id="m122">
<mml:mrow>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x2295;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:msub>
<mml:mi>s</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>E</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>k</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf118">
<mml:math id="m123">
<mml:mrow>
<mml:msubsup>
<mml:mi>G</mml:mi>
<mml:mi>i</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>E</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mn>1</mml:mn>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> The server then verifies if <inline-formula id="inf119">
<mml:math id="m124">
<mml:mrow>
<mml:msubsup>
<mml:mi>G</mml:mi>
<mml:mi>i</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>G</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> If the equality does not hold, <inline-formula id="inf120">
<mml:math id="m125">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> rejects session. If the equality holds, <inline-formula id="inf121">
<mml:math id="m126">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> retrieves the database using <inline-formula id="inf122">
<mml:math id="m127">
<mml:mrow>
<mml:mi>F</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, obtaining <inline-formula id="inf123">
<mml:math id="m128">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>F</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <inline-formula id="inf124">
<mml:math id="m129">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> generates <inline-formula id="inf125">
<mml:math id="m130">
<mml:mrow>
<mml:msub>
<mml:mi>n</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and calculates <inline-formula id="inf126">
<mml:math id="m131">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:msub>
<mml:mi>n</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>E</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>k</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <inline-formula id="inf127">
<mml:math id="m132">
<mml:mrow>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2295;</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf128">
<mml:math id="m133">
<mml:mrow>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mn>2</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2295;</mml:mo>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> Then, calculate <inline-formula id="inf129">
<mml:math id="m134">
<mml:mrow>
<mml:mi>Y</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <inline-formula id="inf130">
<mml:math id="m135">
<mml:mrow>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mn>2</mml:mn>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>F</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and send <inline-formula id="inf131">
<mml:math id="m136">
<mml:mrow>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>Y</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mn>2</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> to the access device <inline-formula id="inf132">
<mml:math id="m137">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>
</p>
<p>
<italic>Step 3:</italic> Access device <inline-formula id="inf133">
<mml:math id="m138">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> receives the message from server <inline-formula id="inf134">
<mml:math id="m139">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> Access device checks <inline-formula id="inf135">
<mml:math id="m140">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mn>2</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, then calculates <inline-formula id="inf136">
<mml:math id="m141">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>U</mml:mi>
<mml:mi>F</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>N</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x2295;</mml:mo>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> &#x3d; <inline-formula id="inf137">
<mml:math id="m142">
<mml:mrow>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2295;</mml:mo>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf138">
<mml:math id="m143">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mn>2</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2295;</mml:mo>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> Then, <inline-formula id="inf139">
<mml:math id="m144">
<mml:mrow>
<mml:mi>F</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>P</mml:mi>
<mml:mi>U</mml:mi>
<mml:mi>F</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf140">
<mml:math id="m145">
<mml:mrow>
<mml:mi>Y</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <inline-formula id="inf141">
<mml:math id="m146">
<mml:mrow>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>R</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>F</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mn>2</mml:mn>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>F</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> is verified. If the value is correct, access device <inline-formula id="inf142">
<mml:math id="m147">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> generates a random number <inline-formula id="inf143">
<mml:math id="m148">
<mml:mrow>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and calculates <inline-formula id="inf144">
<mml:math id="m149">
<mml:mrow>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2295;</mml:mo>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf145">
<mml:math id="m150">
<mml:mrow>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <inline-formula id="inf146">
<mml:math id="m151">
<mml:mrow>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>F</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>. Access device <inline-formula id="inf147">
<mml:math id="m152">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> then sends <inline-formula id="inf148">
<mml:math id="m153">
<mml:mrow>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf149">
<mml:math id="m154">
<mml:mrow>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> to cloud server <inline-formula id="inf150">
<mml:math id="m155">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> .</p>
<p>
<italic>Step 4:</italic> Upon receiving <inline-formula id="inf151">
<mml:math id="m156">
<mml:mrow>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf152">
<mml:math id="m157">
<mml:mrow>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf153">
<mml:math id="m158">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> computes <inline-formula id="inf154">
<mml:math id="m159">
<mml:mrow>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2295;</mml:mo>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <inline-formula id="inf155">
<mml:math id="m160">
<mml:mrow>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>F</mml:mi>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, and verifies the value of <inline-formula id="inf156">
<mml:math id="m161">
<mml:mrow>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. Then, <inline-formula id="inf157">
<mml:math id="m162">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf158">
<mml:math id="m163">
<mml:mrow>
<mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <inline-formula id="inf159">
<mml:math id="m164">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:msub>
<mml:mi>n</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>x</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf160">
<mml:math id="m165">
<mml:mrow>
<mml:msub>
<mml:mi>H</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x2295;</mml:mo>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. Next, calculate <inline-formula id="inf161">
<mml:math id="m166">
<mml:mrow>
<mml:msub>
<mml:mi>Y</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>S</mml:mi>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>H</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>. <inline-formula id="inf162">
<mml:math id="m167">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> sends the message <inline-formula id="inf163">
<mml:math id="m168">
<mml:mrow>
<mml:mfenced open="{" close="}" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>Y</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>H</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:math>
</inline-formula> to user <inline-formula id="inf164">
<mml:math id="m169">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> via a public channel and calculates <inline-formula id="inf165">
<mml:math id="m170">
<mml:mrow>
<mml:msub>
<mml:mi>M</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, sending <inline-formula id="inf166">
<mml:math id="m171">
<mml:mrow>
<mml:msub>
<mml:mi>M</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> to access device <inline-formula id="inf167">
<mml:math id="m172">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula>
</p>
<p>
<italic>Step 5:</italic> Upon receiving the message, the user computes <inline-formula id="inf168">
<mml:math id="m173">
<mml:mrow>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:msub>
<mml:mi>r</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:msub>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>A</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2295;</mml:mo>
<mml:msub>
<mml:mi>H</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>S</mml:mi>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf169">
<mml:math id="m174">
<mml:mrow>
<mml:msubsup>
<mml:mi>Y</mml:mi>
<mml:mi>j</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>S</mml:mi>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>H</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, then verifies whether <inline-formula id="inf170">
<mml:math id="m175">
<mml:mrow>
<mml:msubsup>
<mml:mi>Y</mml:mi>
<mml:mi>j</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
<mml:mo>&#x3d;</mml:mo>
<mml:msub>
<mml:mi>Y</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>.</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> If it holds, then mutual authentication between <inline-formula id="inf171">
<mml:math id="m176">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and server <inline-formula id="inf172">
<mml:math id="m177">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is successfully completed, and a session key is established.</p>
<p>
<italic>Step 6:</italic> Upon receiving the message, <inline-formula id="inf173">
<mml:math id="m178">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> computes <inline-formula id="inf174">
<mml:math id="m179">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
</mml:mrow>
</mml:math>
</inline-formula> <inline-formula id="inf175">
<mml:math id="m180">
<mml:mrow>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and verifies whether <inline-formula id="inf176">
<mml:math id="m181">
<mml:mrow>
<mml:msubsup>
<mml:mi>M</mml:mi>
<mml:mi>j</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>. If the equality holds, mutual authentication between <inline-formula id="inf177">
<mml:math id="m182">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf178">
<mml:math id="m183">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is successfully completed, and a session key is established.</p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Security analysis</title>
<p>In this section, we conduct a security analysis of the proposed scheme under the Random Oracle Model (ROM). Furthermore, additional security properties are examined through semantic evaluation [<xref ref-type="bibr" rid="B45">45</xref>&#x2013;<xref ref-type="bibr" rid="B47">47</xref>].</p>
<sec id="s4-1">
<label>4.1</label>
<title>Formal security proof using ROM</title>
<p>The security of session keys can be formally proven through rigorous mathematical analysis of the protocol within the Random Oracle Model (ROM).</p>
<p>Participants: Entities involved in the scheme include the user <inline-formula id="inf179">
<mml:math id="m184">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, cloud server <inline-formula id="inf180">
<mml:math id="m185">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and the access device <inline-formula id="inf181">
<mml:math id="m186">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. Let <inline-formula id="inf182">
<mml:math id="m187">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf183">
<mml:math id="m188">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>2</mml:mn>
</mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf184">
<mml:math id="m189">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>3</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula> respectively denote instances of the user <inline-formula id="inf185">
<mml:math id="m190">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, cloud server <inline-formula id="inf186">
<mml:math id="m191">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and access device <inline-formula id="inf187">
<mml:math id="m192">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
<p>Accepted: Instance <inline-formula id="inf188">
<mml:math id="m193">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> enters an accepted state when it receives the final scheme message during communication process. The instance <inline-formula id="inf189">
<mml:math id="m194">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> maintains the sequence of all exchanged messages, forming a session identifier for the current session.</p>
<p>Partnering: Instances <inline-formula id="inf190">
<mml:math id="m195">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf191">
<mml:math id="m196">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> are regarded as partners when the following criteria are met:<list list-type="order">
<list-item>
<p>Both instances must be in the accepted state.</p>
</list-item>
<list-item>
<p>
<inline-formula id="inf192">
<mml:math id="m197">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf193">
<mml:math id="m198">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> must have mutually authenticated and share the same session key.</p>
</list-item>
<list-item>
<p>
<inline-formula id="inf194">
<mml:math id="m199">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf195">
<mml:math id="m200">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> must be each other&#x2019;s designated partner.</p>
</list-item>
</list>
</p>
<p>Freshness: Instances <inline-formula id="inf196">
<mml:math id="m201">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf197">
<mml:math id="m202">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> are considered fresh if the adversary <inline-formula id="inf198">
<mml:math id="m203">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> has not obtained their session key using the <inline-formula id="inf199">
<mml:math id="m204">
<mml:mrow>
<mml:mi>R</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>v</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> query.</p>
<p>It is assumed that adversary <inline-formula id="inf200">
<mml:math id="m205">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> has complete control over the communication in the system. <inline-formula id="inf201">
<mml:math id="m206">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> can intercept, eavesdrop and modify messages. In the Random Oracle Model, <inline-formula id="inf202">
<mml:math id="m207">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> can perform simulated queries to compromise the authenticity and confidentiality of key agreement and session keys. The types of queries allowed are as follows:</p>
<p>
<inline-formula id="inf203">
<mml:math id="m208">
<mml:mrow>
<mml:mi>E</mml:mi>
<mml:mi>x</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>t</mml:mi>
<mml:mi>e</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>3</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>: Simulates a passive attack where <inline-formula id="inf204">
<mml:math id="m209">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> obtains all messages exchanged between user <inline-formula id="inf205">
<mml:math id="m210">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, cloud server <inline-formula id="inf206">
<mml:math id="m211">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and the access device <inline-formula id="inf207">
<mml:math id="m212">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
<p>
<inline-formula id="inf208">
<mml:math id="m213">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>: Simulates an active attack. <inline-formula id="inf209">
<mml:math id="m214">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> impersonates instance <inline-formula id="inf210">
<mml:math id="m215">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="normal">&#x3a0;</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and sends message <inline-formula id="inf211">
<mml:math id="m216">
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> to instance <inline-formula id="inf212">
<mml:math id="m217">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="normal">&#x3a0;</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. If <inline-formula id="inf213">
<mml:math id="m218">
<mml:mrow>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is valid, <inline-formula id="inf214">
<mml:math id="m219">
<mml:mrow>
<mml:msub>
<mml:mi mathvariant="normal">&#x3a0;</mml:mi>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> responds appropriately; otherwise, the simulator terminates the query.</p>
<p>
<inline-formula id="inf215">
<mml:math id="m220">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>t</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:mi>a</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>: If <inline-formula id="inf216">
<mml:math id="m221">
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>0</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula>, the user&#x2019;s password is revealed. If <inline-formula id="inf217">
<mml:math id="m222">
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula>, the smart card itself is returned. If <inline-formula id="inf218">
<mml:math id="m223">
<mml:mrow>
<mml:mi>a</mml:mi>
<mml:mo>&#x3d;</mml:mo>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula>, biometric data is provided.</p>
<p>
<inline-formula id="inf219">
<mml:math id="m224">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>t</mml:mi>
<mml:mtext>AD</mml:mtext>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
<mml:msub>
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:msubsup>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>: Allows <inline-formula id="inf220">
<mml:math id="m225">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> to retrieve all information stored in the device node.</p>
<p>
<inline-formula id="inf221">
<mml:math id="m226">
<mml:mrow>
<mml:mi>R</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>v</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>a</mml:mi>
<mml:mi>l</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>: Allows <inline-formula id="inf222">
<mml:math id="m227">
<mml:mrow>
<mml:mi>A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> to obtain session key generated by instance <inline-formula id="inf223">
<mml:math id="m228">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and its partner.</p>
<p>
<inline-formula id="inf224">
<mml:math id="m229">
<mml:mrow>
<mml:mi>T</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>t</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>
<italic>:</italic> <inline-formula id="inf225">
<mml:math id="m230">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> initiates this challenge query on a legitimate instance <inline-formula id="inf226">
<mml:math id="m231">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> of <inline-formula id="inf227">
<mml:math id="m232">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf228">
<mml:math id="m233">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. <inline-formula id="inf229">
<mml:math id="m234">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> fair coin c is tossed to determine the output; If c &#x3d; 1, the real session key is returned; If c &#x3d; 0, a random string is returned; In other cases, the output is null. Only A knows the outcome of the coin toss.</p>
<p>Semantic Security: <inline-formula id="inf230">
<mml:math id="m235">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> can perform multiple <inline-formula id="inf231">
<mml:math id="m236">
<mml:mrow>
<mml:mi>T</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> queries on <inline-formula id="inf232">
<mml:math id="m237">
<mml:mrow>
<mml:msub>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and guess a bit value c. Let <inline-formula id="inf233">
<mml:math id="m238">
<mml:mrow>
<mml:mi mathvariant="script">P</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> denote the authentication and key agreement protocol. If c &#x3d; c, <inline-formula id="inf234">
<mml:math id="m239">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> wins the game and breaks the semantic security of <inline-formula id="inf235">
<mml:math id="m240">
<mml:mrow>
<mml:mi mathvariant="script">P</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>. The event where <inline-formula id="inf236">
<mml:math id="m241">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> wins is denoted as Succ. Thus, we have:<disp-formula id="e6">
<mml:math id="m242">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>d</mml:mi>
<mml:msubsup>
<mml:mi>v</mml:mi>
<mml:mi mathvariant="script">P</mml:mi>
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>K</mml:mi>
<mml:mi>A</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2264;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msubsup>
<mml:mi>q</mml:mi>
<mml:mi>h</mml:mi>
<mml:mn>2</mml:mn>
</mml:msubsup>
</mml:mrow>
<mml:mrow>
<mml:msup>
<mml:mn>2</mml:mn>
<mml:mi>l</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfrac>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>2</mml:mn>
<mml:mo>&#x2061;</mml:mo>
<mml:mi mathvariant="italic">max</mml:mi>
<mml:mrow>
<mml:mfenced open="{" close="}" separators="&#x7c;">
<mml:mrow>
<mml:msup>
<mml:mi>C</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
<mml:msubsup>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:msup>
<mml:mi>s</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msub>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mrow>
<mml:msup>
<mml:mn>2</mml:mn>
<mml:mi>l</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfrac>
<mml:mo>,</mml:mo>
<mml:mi>&#x3b5;</mml:mi>
<mml:msub>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>2</mml:mn>
<mml:mi>A</mml:mi>
<mml:mi>d</mml:mi>
<mml:msup>
<mml:mi>v</mml:mi>
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>M</mml:mi>
<mml:mi>D</mml:mi>
<mml:mi>L</mml:mi>
<mml:mi>P</mml:mi>
</mml:mrow>
</mml:msup>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
<label>(6)</label>
</disp-formula>where <inline-formula id="inf237">
<mml:math id="m243">
<mml:mrow>
<mml:msub>
<mml:mi>q</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf238">
<mml:math id="m244">
<mml:mrow>
<mml:msub>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf239">
<mml:math id="m245">
<mml:mrow>
<mml:mi>l</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf240">
<mml:math id="m246">
<mml:mrow>
<mml:mi>&#x3b5;</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> respectively denote the number of random oracle queries, the number of <italic>Send</italic> queries, the output length of random oracle and the probability of a false positive by the simulation extractor. The parameters <inline-formula id="inf241">
<mml:math id="m247">
<mml:mrow>
<mml:msup>
<mml:mi mathvariant="normal">c</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf242">
<mml:math id="m248">
<mml:mrow>
<mml:msup>
<mml:mi mathvariant="normal">s</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> are those of the Zipf distribution.</p>
<p>Proof: Five distinct games <inline-formula id="inf243">
<mml:math id="m249">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>G</mml:mi>
<mml:mi>M</mml:mi>
</mml:mrow>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> are defined for formal analysis. Let <inline-formula id="inf244">
<mml:math id="m250">
<mml:mrow>
<mml:msub>
<mml:mtext>Succ</mml:mtext>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> denote the success event in game <inline-formula id="inf245">
<mml:math id="m251">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>G</mml:mi>
<mml:mi>M</mml:mi>
</mml:mrow>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf246">
<mml:math id="m252">
<mml:mrow>
<mml:mi mathvariant="italic">Pr</mml:mi>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>c</mml:mi>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> represent the probability that adversary <inline-formula id="inf247">
<mml:math id="m253">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> correctly guesses the value of <inline-formula id="inf248">
<mml:math id="m254">
<mml:mrow>
<mml:mi mathvariant="normal">c</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> and wins the game in <inline-formula id="inf249">
<mml:math id="m255">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>G</mml:mi>
<mml:mi>M</mml:mi>
</mml:mrow>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. <inline-formula id="inf250">
<mml:math id="m256">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> initiates the <italic>Test</italic> query and attempts to guess the value of <inline-formula id="inf251">
<mml:math id="m257">
<mml:mrow>
<mml:mi mathvariant="normal">c</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
<p>Game <inline-formula id="inf252">
<mml:math id="m258">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="bold-italic">G</mml:mi>
<mml:mi mathvariant="bold-italic">M</mml:mi>
</mml:mrow>
<mml:mn mathvariant="bold">0</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>:</p>
<p>
<inline-formula id="inf253">
<mml:math id="m259">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>G</mml:mi>
<mml:mi>M</mml:mi>
</mml:mrow>
<mml:mn>0</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> simulates a real-world attack on the proposed protocol <inline-formula id="inf254">
<mml:math id="m260">
<mml:mrow>
<mml:mi mathvariant="script">P</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>. Adversary <inline-formula id="inf255">
<mml:math id="m261">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> must randomly choose a bit ccc before the game begins. By definition, we obtain:<disp-formula id="e7">
<mml:math id="m262">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:msubsup>
<mml:mrow>
<mml:mi>d</mml:mi>
<mml:mi>v</mml:mi>
</mml:mrow>
<mml:mi mathvariant="script">P</mml:mi>
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>K</mml:mi>
<mml:mi>A</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mo>&#x3d;</mml:mo>
<mml:mrow>
<mml:mfenced open="|" close="|" separators="&#x7c;">
<mml:mrow>
<mml:mn>2</mml:mn>
<mml:mo>&#x2061;</mml:mo>
<mml:mi mathvariant="italic">Pr</mml:mi>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>c</mml:mi>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mn>0</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
<label>(7)</label>
</disp-formula>
</p>
<p>Game <inline-formula id="inf256">
<mml:math id="m263">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="bold-italic">G</mml:mi>
<mml:mi mathvariant="bold-italic">M</mml:mi>
</mml:mrow>
<mml:mn mathvariant="bold">1</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>:</p>
<p>In this game, within the random oracle model, adversary <inline-formula id="inf257">
<mml:math id="m264">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> performs a passive eavesdropping attack. However, based on the messages transmitted over the public channel, <inline-formula id="inf258">
<mml:math id="m265">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is still unable to compute the session key or obtain any other secret information. Therefore, we have:<disp-formula id="e8">
<mml:math id="m266">
<mml:mrow>
<mml:mi mathvariant="italic">Pr</mml:mi>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>c</mml:mi>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mn>1</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mi mathvariant="normal">P</mml:mi>
<mml:mi>r</mml:mi>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>c</mml:mi>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mn>0</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
<label>(8)</label>
</disp-formula>
</p>
<p>Game <inline-formula id="inf259">
<mml:math id="m267">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="bold-italic">G</mml:mi>
<mml:mi mathvariant="bold-italic">M</mml:mi>
</mml:mrow>
<mml:mn mathvariant="bold">2</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>:</p>
<p>Building upon the previous game, <inline-formula id="inf260">
<mml:math id="m268">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>G</mml:mi>
<mml:mi>M</mml:mi>
</mml:mrow>
<mml:mn>2</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> additionally includes simulations of the <italic>Send</italic> and <italic>Hash</italic> queries. Assuming that <inline-formula id="inf261">
<mml:math id="m269">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> attempts to find a collision in the hash function, the collision probability based on the birthday paradox is given by:<disp-formula id="e9">
<mml:math id="m270">
<mml:mrow>
<mml:mrow>
<mml:mfenced open="|" close="|" separators="&#x7c;">
<mml:mrow>
<mml:mi mathvariant="italic">Pr</mml:mi>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>c</mml:mi>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mn>2</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:mi mathvariant="italic">Pr</mml:mi>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>c</mml:mi>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mn>1</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2264;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msubsup>
<mml:mi>q</mml:mi>
<mml:mi>h</mml:mi>
<mml:mn>2</mml:mn>
</mml:msubsup>
</mml:mrow>
<mml:mrow>
<mml:msup>
<mml:mn>2</mml:mn>
<mml:mrow>
<mml:mi>l</mml:mi>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:msup>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
</mml:math>
<label>(9)</label>
</disp-formula>
</p>
<p>Game <inline-formula id="inf262">
<mml:math id="m271">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="bold-italic">G</mml:mi>
<mml:mi mathvariant="bold-italic">M</mml:mi>
</mml:mrow>
<mml:mn mathvariant="bold">3</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>:</p>
<p>Building upon Game <inline-formula id="inf263">
<mml:math id="m272">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>G</mml:mi>
<mml:mi>M</mml:mi>
</mml:mrow>
<mml:mn>2</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, Game <inline-formula id="inf264">
<mml:math id="m273">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>G</mml:mi>
<mml:mi>M</mml:mi>
</mml:mrow>
<mml:mn>3</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> introduces the <inline-formula id="inf265">
<mml:math id="m274">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> query to simulate the security of multi-factor authentication. Through this query, adversary <inline-formula id="inf266">
<mml:math id="m275">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> can interact with the user <inline-formula id="inf267">
<mml:math id="m276">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf268">
<mml:math id="m277">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> to attempt to obtain the session key. Assume that adversary <inline-formula id="inf269">
<mml:math id="m278">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> can compromise at most two authentication factors. This leads to the following three scenarios:<list list-type="order">
<list-item>
<p>
<inline-formula id="inf270">
<mml:math id="m279">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> obtains the smart card and the user password: That is, by issuing <inline-formula id="inf271">
<mml:math id="m280">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>t</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:mn>0</mml:mn>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf272">
<mml:math id="m281">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>t</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, adversary <inline-formula id="inf273">
<mml:math id="m282">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> gains access to the smart card and password. In this case, <inline-formula id="inf274">
<mml:math id="m283">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> may attempt to retrieve the biometric feature <inline-formula id="inf275">
<mml:math id="m284">
<mml:mrow>
<mml:msub>
<mml:mi>B</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> through <italic>Send</italic> queries. The success probability is: <inline-formula id="inf276">
<mml:math id="m285">
<mml:mrow>
<mml:mfrac>
<mml:mrow>
<mml:msub>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mrow>
<mml:msup>
<mml:mn>2</mml:mn>
<mml:mi>l</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
</list-item>
<list-item>
<p>
<inline-formula id="inf277">
<mml:math id="m286">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> obtains the password <inline-formula id="inf278">
<mml:math id="m287">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mi>W</mml:mi>
</mml:mrow>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and the biometric <inline-formula id="inf279">
<mml:math id="m288">
<mml:mrow>
<mml:msub>
<mml:mi>B</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>: That is, <inline-formula id="inf280">
<mml:math id="m289">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> issues <inline-formula id="inf281">
<mml:math id="m290">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>t</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:mn>0</mml:mn>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf282">
<mml:math id="m291">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>t</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>. However, without access to the smart card&#x2019;s internal data, the probability that <inline-formula id="inf283">
<mml:math id="m292">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> successfully impersonates the user <inline-formula id="inf284">
<mml:math id="m293">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is negligible.</p>
</list-item>
<list-item>
<p>
<inline-formula id="inf285">
<mml:math id="m294">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> obtains the smart card and biometric <inline-formula id="inf286">
<mml:math id="m295">
<mml:mrow>
<mml:msub>
<mml:mi>B</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>: That is, by issuing <inline-formula id="inf287">
<mml:math id="m296">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>t</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf288">
<mml:math id="m297">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>t</mml:mi>
<mml:mspace width="0.17em"/>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msubsup>
<mml:mi>I</mml:mi>
<mml:mi>i</mml:mi>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>, adversary <inline-formula id="inf289">
<mml:math id="m298">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> acquires the smart card and biometric data. In this case, <inline-formula id="inf290">
<mml:math id="m299">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> may attempt to recover the password <inline-formula id="inf291">
<mml:math id="m300">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mi>W</mml:mi>
</mml:mrow>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> via <italic>Send</italic> queries. The success probability is: <inline-formula id="inf292">
<mml:math id="m301">
<mml:mrow>
<mml:msup>
<mml:mi>C</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
<mml:msubsup>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:msup>
<mml:mi>s</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula>
</p>
</list-item>
</list>
</p>
<p>In addition, due to the use of fuzzy extractors, false positives may occur. The probability that adversary <inline-formula id="inf293">
<mml:math id="m302">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> successfully deceives the reproduction function <italic>Rep</italic>(&#x22c5;) is bounded by <inline-formula id="inf294">
<mml:math id="m303">
<mml:mrow>
<mml:mi>&#x3b5;</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, and the success rate for such deception through <italic>Send</italic> queries is: <inline-formula id="inf295">
<mml:math id="m304">
<mml:mrow>
<mml:mi>&#x3b5;</mml:mi>
<mml:msub>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
<p>Therefore, we obtain the following result:<disp-formula id="e10">
<mml:math id="m305">
<mml:mrow>
<mml:mrow>
<mml:mfenced open="|" close="|" separators="&#x7c;">
<mml:mrow>
<mml:mi mathvariant="italic">Pr</mml:mi>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>c</mml:mi>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mn>3</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:mi mathvariant="italic">Pr</mml:mi>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>c</mml:mi>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mn>2</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2264;</mml:mo>
<mml:mi>max</mml:mi>
<mml:mrow>
<mml:mfenced open="{" close="}" separators="&#x7c;">
<mml:mrow>
<mml:msup>
<mml:mi>C</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
<mml:msubsup>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:msup>
<mml:mi>s</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msub>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mrow>
<mml:msup>
<mml:mn>2</mml:mn>
<mml:mi>l</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfrac>
<mml:mo>,</mml:mo>
<mml:mi>&#x3b5;</mml:mi>
<mml:msub>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
<label>(10)</label>
</disp-formula>
</p>
<p>Game <inline-formula id="inf296">
<mml:math id="m306">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi mathvariant="bold-italic">G</mml:mi>
<mml:mi mathvariant="bold-italic">M</mml:mi>
</mml:mrow>
<mml:mn mathvariant="bold">4</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>:</p>
<p>In Game <inline-formula id="inf297">
<mml:math id="m307">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>G</mml:mi>
<mml:mi>M</mml:mi>
</mml:mrow>
<mml:mn>4</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, adversary <inline-formula id="inf298">
<mml:math id="m308">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> is allowed to perform the <inline-formula id="inf299">
<mml:math id="m309">
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>o</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>r</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>p</mml:mi>
<mml:mi>t</mml:mi>
<mml:mtext>AD</mml:mtext>
</mml:mrow>
</mml:math>
</inline-formula> query, which simulates the physical capture of a sensor node. Through this query, <inline-formula id="inf300">
<mml:math id="m310">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> obtains the information stored in <inline-formula id="inf301">
<mml:math id="m311">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. In addition, <inline-formula id="inf302">
<mml:math id="m312">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> can use the <italic>Execute</italic> query to eavesdrop on all messages exchanged during the authentication and key agreement process. Although adversary <inline-formula id="inf303">
<mml:math id="m313">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> attempts to compute the session key, decryption is not possible because <inline-formula id="inf304">
<mml:math id="m314">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> lacks the user&#x2019;s secret paramaters. Furthermore, the adversary cannot obtain the necessary random values used in key generation. As a result, in order to derive the session key, <inline-formula id="inf305">
<mml:math id="m315">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> must solve the CMDLP problem. Let <inline-formula id="inf306">
<mml:math id="m316">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>d</mml:mi>
<mml:msup>
<mml:mi>v</mml:mi>
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>M</mml:mi>
<mml:mi>D</mml:mi>
<mml:mi>L</mml:mi>
<mml:mi>P</mml:mi>
</mml:mrow>
</mml:msup>
</mml:mrow>
</mml:math>
</inline-formula> denote the advantage of adversary <inline-formula id="inf307">
<mml:math id="m317">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> in solving the CMDLP problem within time t. Therefore, we conclude:<disp-formula id="e11">
<mml:math id="m318">
<mml:mrow>
<mml:mrow>
<mml:mfenced open="|" close="|" separators="&#x7c;">
<mml:mrow>
<mml:mi mathvariant="italic">Pr</mml:mi>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>c</mml:mi>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mn>4</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2212;</mml:mo>
<mml:mi mathvariant="italic">Pr</mml:mi>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>c</mml:mi>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mn>3</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2264;</mml:mo>
<mml:mi>A</mml:mi>
<mml:mi>d</mml:mi>
<mml:msup>
<mml:mi>v</mml:mi>
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>M</mml:mi>
<mml:mi>D</mml:mi>
<mml:mi>L</mml:mi>
<mml:mi>P</mml:mi>
</mml:mrow>
</mml:msup>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
<label>(11)</label>
</disp-formula>
</p>
<p>In Game <inline-formula id="inf308">
<mml:math id="m319">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>G</mml:mi>
<mml:mi>M</mml:mi>
</mml:mrow>
<mml:mn>4</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, all random oracle simulation queries are executed. Therefore, we have:<disp-formula id="e12">
<mml:math id="m320">
<mml:mrow>
<mml:mi mathvariant="italic">Pr</mml:mi>
<mml:mrow>
<mml:mfenced open="[" close="]" separators="&#x7c;">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:mi>u</mml:mi>
<mml:mi>c</mml:mi>
<mml:msub>
<mml:mi>c</mml:mi>
<mml:mn>4</mml:mn>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x3d;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mrow>
<mml:mn>2</mml:mn>
</mml:mrow>
</mml:mfrac>
</mml:mrow>
</mml:math>
<label>(12)</label>
</disp-formula>
</p>
<p>According to <xref ref-type="disp-formula" rid="e6">Equations 6</xref>&#x2013;<xref ref-type="disp-formula" rid="e12">12</xref>, we obtain: <inline-formula id="inf309">
<mml:math id="m321">
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>d</mml:mi>
<mml:msubsup>
<mml:mi>v</mml:mi>
<mml:mi mathvariant="script">P</mml:mi>
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>K</mml:mi>
<mml:mi>A</mml:mi>
</mml:mrow>
</mml:msubsup>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2264;</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msubsup>
<mml:mi>q</mml:mi>
<mml:mi>h</mml:mi>
<mml:mn>2</mml:mn>
</mml:msubsup>
</mml:mrow>
<mml:mrow>
<mml:msup>
<mml:mn>2</mml:mn>
<mml:mi>l</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfrac>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>2</mml:mn>
<mml:mo>&#x2061;</mml:mo>
<mml:mi mathvariant="italic">max</mml:mi>
<mml:mrow>
<mml:mfenced open="{" close="}" separators="&#x7c;">
<mml:mrow>
<mml:msup>
<mml:mi>C</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
<mml:msubsup>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
<mml:msup>
<mml:mi>s</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msup>
</mml:msubsup>
<mml:mo>,</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msub>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
<mml:mrow>
<mml:msup>
<mml:mn>2</mml:mn>
<mml:mi>l</mml:mi>
</mml:msup>
</mml:mrow>
</mml:mfrac>
<mml:mo>,</mml:mo>
<mml:mi>&#x3b5;</mml:mi>
<mml:msub>
<mml:mi>q</mml:mi>
<mml:mrow>
<mml:mi>s</mml:mi>
<mml:mi>e</mml:mi>
<mml:mi>n</mml:mi>
<mml:mi>d</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>2</mml:mn>
<mml:mi>A</mml:mi>
<mml:mi>d</mml:mi>
<mml:msup>
<mml:mi>v</mml:mi>
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>M</mml:mi>
<mml:mi>D</mml:mi>
<mml:mi>L</mml:mi>
<mml:mi>P</mml:mi>
</mml:mrow>
</mml:msup>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:mi>t</mml:mi>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>. The above sequence of games demonstrates that the protocol is provably secure under the Random Oracle Model (ROM).</p>
</sec>
<sec id="s4-2">
<label>4.2</label>
<title>Semantic analysis</title>
<p>In this section, we discuss the main safety features. We have conducted a comprehensive analysis of the plan to demonstrate that the proposed approach can achieve these safety features [<xref ref-type="bibr" rid="B48">48</xref>].<list list-type="order">
<list-item>
<p>User Anonymity: During the registration phase, message is transmitted over a secure channel. Therefore, if an attacker attempts to launch an illegal attack, their only option is to perform cryptanalysis using the information intercepted from the user&#x2019;s smart card (SC) and non-secure channel. Suppose the attacker has stolen the user&#x2019;s smart card SC and conducted a power analysis attack to extract the parameters stored in the card. Even so, the SC does not contain the user&#x2019;s identity information. Any attempt to recover the identity would inevitably encounter the difficulty of inverting the hash function. Moreover, even if the attacker intercepts communication over the non-secure channel, the use of anonymous identities by the user prevents the attacker from obtaining the user&#x2019;s real identity.</p>
</list-item>
<list-item>
<p>Replay Attack: Replay attack refers to the scenario where an attacker intercepts a message that has previously been authenticated by <inline-formula id="inf310">
<mml:math id="m322">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, the cloud server, or <inline-formula id="inf311">
<mml:math id="m323">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and then retransmits it to <inline-formula id="inf312">
<mml:math id="m324">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> the cloud server, or <inline-formula id="inf313">
<mml:math id="m325">
<mml:mrow>
<mml:msub>
<mml:mi>S</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> in order to deceive them. However, throughout the communication process, fresh timestamps and random numbers are always used to ensure security. The difficulty of the Chebyshev Polynomial-Based Diffie-Hellman Problem (<inline-formula id="inf314">
<mml:math id="m326">
<mml:mrow>
<mml:mtext>CMDLP</mml:mtext>
</mml:mrow>
</mml:math>
</inline-formula>) ensures that the attacker cannot alter the message. Therefore, the protocol effectively defends against replay attacks.</p>
</list-item>
<list-item>
<p>User Impersonation Attack: Whether it is an unregistered illegal user or a malicious legitimate user, in order to impersonate a legitimate user <inline-formula id="inf315">
<mml:math id="m327">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and complete the subsequent authentication process, the attacker must successfully obtain <inline-formula id="inf316">
<mml:math id="m328">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>&#x27;s <inline-formula id="inf317">
<mml:math id="m329">
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, login password <inline-formula id="inf318">
<mml:math id="m330">
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:msub>
<mml:mi>W</mml:mi>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and input the biometric information <inline-formula id="inf319">
<mml:math id="m331">
<mml:mrow>
<mml:msubsup>
<mml:mi>B</mml:mi>
<mml:mi>i</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula>. Even if the attacker obtains <inline-formula id="inf320">
<mml:math id="m332">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>&#x27;s smart card and uses energy analysis attacks to extract the relevant parameters from the card, along with the previously intercepted communication data, the mathematical challenges they face in obtaining the correct <inline-formula id="inf321">
<mml:math id="m333">
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and <inline-formula id="inf322">
<mml:math id="m334">
<mml:mrow>
<mml:msubsup>
<mml:mi>B</mml:mi>
<mml:mi>i</mml:mi>
<mml:mo>&#x2032;</mml:mo>
</mml:msubsup>
</mml:mrow>
</mml:math>
</inline-formula> remain unsolvable based on the current foundation.</p>
</list-item>
<list-item>
<p>Session Key Security: Based on the proposed scheme, after mutual authentication and key exchange between the user and the device, a session key for subsequent communication can be negotiated. The session key is given by <inline-formula id="inf323">
<mml:math id="m335">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula>.</p>
</list-item>
<list-item>
<p>Perfect Forward Security: The session key between the user and the device node is denoted as <inline-formula id="inf324">
<mml:math id="m336">
<mml:mrow>
<mml:mi>S</mml:mi>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mrow>
<mml:mi>j</mml:mi>
<mml:mi>i</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x3d;</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>Q</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:mi>h</mml:mi>
<mml:mrow>
<mml:mfenced open="(" close=")" separators="&#x7c;">
<mml:mrow>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>v</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>,</mml:mo>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:mfenced>
</mml:mrow>
</mml:mrow>
</mml:math>
</inline-formula> and this key depends on the user and the random number. Suppose an attacker has access to the long-term keys of the protocol participants, but in order to obtain the random numbers associated with the session key, the attacker must solve the difficult Chaos Mapping Computationally Hard Discrete Logarithm Problem (CMDLP). Additionally, the attacker cannot obtain the user&#x2019;s identity, making it impossible to compute the session key. Therefore, this protocol ensures perfect forward security.</p>
</list-item>
<list-item>
<p>Man-in-the-middle attacks: Assume that <inline-formula id="inf325">
<mml:math id="m337">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> can eavesdrop on the messages transmitted between the user <inline-formula id="inf326">
<mml:math id="m338">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and the cloud server over a public channel. However, <inline-formula id="inf327">
<mml:math id="m339">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> cannot obtain the user&#x2019;s <inline-formula id="inf328">
<mml:math id="m340">
<mml:mrow>
<mml:mi>I</mml:mi>
<mml:msub>
<mml:mi>D</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, password <inline-formula id="inf329">
<mml:math id="m341">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mi>W</mml:mi>
</mml:mrow>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and biometric information <inline-formula id="inf330">
<mml:math id="m342">
<mml:mrow>
<mml:msub>
<mml:mi>B</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. Therefore, even if <inline-formula id="inf331">
<mml:math id="m343">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> tampers with the authentication and key exchange request message <inline-formula id="inf332">
<mml:math id="m344">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>M</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>g</mml:mi>
</mml:mrow>
<mml:mn>1</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> from user <inline-formula id="inf333">
<mml:math id="m345">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, they will still be unable to authenticate through cloud server. Similarly, <inline-formula id="inf334">
<mml:math id="m346">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> does not know the device node&#x2019;s secret parameter, so they cannot complete the authentication even after tampering with the messages <inline-formula id="inf335">
<mml:math id="m347">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>M</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>g</mml:mi>
</mml:mrow>
<mml:mn>2</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf336">
<mml:math id="m348">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>M</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>g</mml:mi>
</mml:mrow>
<mml:mn>3</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> transmitted over the public channel.</p>
</list-item>
<list-item>
<p>Insider Privilege Attack: Insider Privilege Attack refers to a situation where a legitimate system administrator turns into a malicious attacker and exploits their legitimate privileges to access confidential system information. As a result, insider privilege attacks often pose a greater threat than external attacks. In this protocol, once <inline-formula id="inf337">
<mml:math id="m349">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> gains cloud server&#x2019;s privileges, they can access the user&#x2019;s information and the user&#x2019;s smart card SC. Then, <inline-formula id="inf338">
<mml:math id="m350">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> could use side-channel attacks to extract data stored in the smart card SC. Although attacker <inline-formula id="inf339">
<mml:math id="m351">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> may link the anonymous identity with the smart card SC, they cannot guess the user&#x2019;s password <inline-formula id="inf340">
<mml:math id="m352">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>P</mml:mi>
<mml:mi>W</mml:mi>
</mml:mrow>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, nor can they compute the biometric value <inline-formula id="inf341">
<mml:math id="m353">
<mml:mrow>
<mml:msub>
<mml:mi>B</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. Therefore, this protocol is resistant to insider privilege attacks.</p>
</list-item>
<list-item>
<p>Mutual Authentication: In this protocol, mutual authentication is achieved between the user <inline-formula id="inf342">
<mml:math id="m354">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and the device node <inline-formula id="inf343">
<mml:math id="m355">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> through cloud server. Specifically, user <inline-formula id="inf344">
<mml:math id="m356">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and the cloud server perform mutual authentication using verification parameters <inline-formula id="inf345">
<mml:math id="m357">
<mml:mrow>
<mml:msub>
<mml:mi>G</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. Similarly, the cloud server and the device node <inline-formula id="inf346">
<mml:math id="m358">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> achieve mutual authentication using verification parameters <inline-formula id="inf347">
<mml:math id="m359">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>Y</mml:mi>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. Therefore, this protocol enables mutual authentication.</p>
</list-item>
<list-item>
<p>Device Node Forgery Attack: Suppose attacker <inline-formula id="inf348">
<mml:math id="m360">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> forges a legitimate device node <inline-formula id="inf349">
<mml:math id="m361">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> to create message <inline-formula id="inf350">
<mml:math id="m362">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>M</mml:mi>
<mml:mi>s</mml:mi>
<mml:mi>g</mml:mi>
</mml:mrow>
<mml:mn>3</mml:mn>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. Attacker <inline-formula id="inf351">
<mml:math id="m363">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> generates a random number <inline-formula id="inf352">
<mml:math id="m364">
<mml:mrow>
<mml:msub>
<mml:mi>h</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and attempts to compute <inline-formula id="inf353">
<mml:math id="m365">
<mml:mrow>
<mml:msub>
<mml:mi>K</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf354">
<mml:math id="m366">
<mml:mrow>
<mml:msub>
<mml:mi>C</mml:mi>
<mml:mi>j</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. However, without knowing the secret parameter, attacker <inline-formula id="inf355">
<mml:math id="m367">
<mml:mrow>
<mml:mi mathvariant="script">A</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> cannot generate a legitimate device node&#x2019;s message. Therefore, this scheme is resistant to device node forgery attacks.</p>
</list-item>
</list>
</p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Performance analysis</title>
<p>In this subsection, we compare the proposed scheme with other existing scheme.</p>
<sec id="s5-1">
<label>5.1</label>
<title>Function</title>
<p>In this subsection, the proposed scheme is compared with other existing protocols. The proposed scheme can effectively resist various types of attacks and largely meets the relevant security and functional requirements. In the table, a check mark (&#x221a;) indicates that the protocol satisfies the corresponding security or functional requirement, while a cross mark (&#xd7;) indicates that it does not. F1&#x2013;F10 represent abbreviations for different attack types and functional features, with corresponding explanations provided below <xref ref-type="table" rid="T2">Table 2</xref>.</p>
<table-wrap id="T2" position="float">
<label>TABLE 2</label>
<caption>
<p>Function comparison.</p>
</caption>
<table>
<thead valign="top">
<tr>
<th align="center">Function</th>
<th align="center">[<xref ref-type="bibr" rid="B42">42</xref>]</th>
<th align="center">[<xref ref-type="bibr" rid="B43">43</xref>]</th>
<th align="center">[<xref ref-type="bibr" rid="B44">44</xref>]</th>
<th align="center">[<xref ref-type="bibr" rid="B45">45</xref>]</th>
<th align="center">[<xref ref-type="bibr" rid="B46">46</xref>]</th>
<th align="center">Our</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td align="center">F1</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#xd7;</td>
<td align="center">&#x221a;</td>
</tr>
<tr>
<td align="center">F2</td>
<td align="center">&#xd7;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
</tr>
<tr>
<td align="center">F3</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
</tr>
<tr>
<td align="center">F4</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
</tr>
<tr>
<td align="center">F5</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#xd7;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
</tr>
<tr>
<td align="center">F6</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
</tr>
<tr>
<td align="center">F7</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
</tr>
<tr>
<td align="center">F8</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
</tr>
<tr>
<td align="center">F9</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#xd7;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
</tr>
<tr>
<td align="center">F10</td>
<td align="center">&#x221a;</td>
<td align="center">&#xd7;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
<td align="center">&#x221a;</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn>
<p>F1, User Anonymity; F2, Replay Attack; F3, User Impersonation Attack; F4, Session Key Security; F5, Perfect Forward Security; F6, Man-in-the-middle attacks; F7, Insider Privilege Attack; F8, Mutual Authentication; F9, Device Node Forgery Attack; F10, Temporary Secret Disclosure Attack.</p>
</fn>
</table-wrap-foot>
</table-wrap>
</sec>
<sec id="s5-2">
<label>5.2</label>
<title>Computation overhead</title>
<p>This subsection presents a comparison of the computational overhead of the proposed schemes. The comparison is based on the computational efforts required by the protocol entities during the authentication and key agreement processes. The computation times are uniformly defined as follows: hash function, elliptic curve scalar multiplication, and chaotic map computation cost are denoted as <inline-formula id="inf356">
<mml:math id="m368">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
<mml:mo>&#x2248;</mml:mo>
<mml:mn>0.00038</mml:mn>
<mml:mi>m</mml:mi>
<mml:mi>s</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula>, <inline-formula id="inf357">
<mml:math id="m369">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2248;</mml:mo>
<mml:mn>0.5078</mml:mn>
<mml:mi>m</mml:mi>
<mml:mi>s</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> and <inline-formula id="inf358">
<mml:math id="m370">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mtext>&#x2009;</mml:mtext>
<mml:mi>T</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2248;</mml:mo>
<mml:mn>0.3118</mml:mn>
<mml:mi>m</mml:mi>
<mml:mi>s</mml:mi>
</mml:mrow>
</mml:math>
</inline-formula> , respectively.</p>
<p>As shown in <xref ref-type="table" rid="T3">Table 3</xref> and <xref ref-type="fig" rid="F4">Figure 4</xref>, the proposed scheme exhibits significant advantages in multiple aspects. In terms of total computational cost, the Our scheme has a total of <inline-formula id="inf359">
<mml:math id="m371">
<mml:mrow>
<mml:mn>6</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>25</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, which is among the lowest compared to other schemes. Although the usage of <inline-formula id="inf360">
<mml:math id="m372">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is slightly higher, the amount of <inline-formula id="inf361">
<mml:math id="m373">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula> is relatively lower, indicating a well-balanced design between complex and regular computations, thus leading to higher efficiency in resource utilization.</p>
<table-wrap id="T3" position="float">
<label>TABLE 3</label>
<caption>
<p>Comparison on computation overhead.</p>
</caption>
<table>
<thead valign="top">
<tr>
<th align="center">Scheme</th>
<th align="center">User (<inline-formula id="inf362">
<mml:math id="m374">
<mml:mrow>
<mml:msub>
<mml:mi>U</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>)</th>
<th align="center">Cloud server (<inline-formula id="inf363">
<mml:math id="m375">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>C</mml:mi>
<mml:mi>S</mml:mi>
</mml:mrow>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>)</th>
<th align="center">Access device (<inline-formula id="inf364">
<mml:math id="m376">
<mml:mrow>
<mml:msub>
<mml:mrow>
<mml:mi>A</mml:mi>
<mml:mi>D</mml:mi>
</mml:mrow>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>)</th>
<th align="center">Total</th>
<th align="center">Total time (ms)</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td align="center">[<xref ref-type="bibr" rid="B42">42</xref>]</td>
<td align="center">
<inline-formula id="inf365">
<mml:math id="m377">
<mml:mrow>
<mml:mn>3</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>9</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf366">
<mml:math id="m378">
<mml:mrow>
<mml:mn>2</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>8</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf367">
<mml:math id="m379">
<mml:mrow>
<mml:mn>3</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>5</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf368">
<mml:math id="m380">
<mml:mrow>
<mml:mn>8</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>22</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">4.07</td>
</tr>
<tr>
<td align="center">[<xref ref-type="bibr" rid="B43">43</xref>]</td>
<td align="center">
<inline-formula id="inf369">
<mml:math id="m381">
<mml:mrow>
<mml:mn>3</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>11</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf370">
<mml:math id="m382">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>11</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf371">
<mml:math id="m383">
<mml:mrow>
<mml:mn>5</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:msub>
<mml:mrow>
<mml:mn>2</mml:mn>
<mml:mi>T</mml:mi>
</mml:mrow>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf372">
<mml:math id="m384">
<mml:mrow>
<mml:mn>6</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>24</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">1.88</td>
</tr>
<tr>
<td align="center">[<xref ref-type="bibr" rid="B44">44</xref>]</td>
<td align="center">
<inline-formula id="inf373">
<mml:math id="m385">
<mml:mrow>
<mml:mn>4</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>10</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf374">
<mml:math id="m386">
<mml:mrow>
<mml:mn>3</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>4</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf375">
<mml:math id="m387">
<mml:mrow>
<mml:mn>4</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>3</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf376">
<mml:math id="m388">
<mml:mrow>
<mml:mn>11</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>17</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">5.59</td>
</tr>
<tr>
<td align="center">[<xref ref-type="bibr" rid="B45">45</xref>]</td>
<td align="center">
<inline-formula id="inf377">
<mml:math id="m389">
<mml:mrow>
<mml:mn>4</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>5</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">--</td>
<td align="center">
<inline-formula id="inf378">
<mml:math id="m390">
<mml:mrow>
<mml:mn>4</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>3</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf379">
<mml:math id="m391">
<mml:mrow>
<mml:mn>8</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>8</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">2.49</td>
</tr>
<tr>
<td align="center">[<xref ref-type="bibr" rid="B46">46</xref>]</td>
<td align="center">
<inline-formula id="inf380">
<mml:math id="m392">
<mml:mrow>
<mml:mn>2</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>9</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf381">
<mml:math id="m393">
<mml:mrow>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>10</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf382">
<mml:math id="m394">
<mml:mrow>
<mml:mn>5</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf383">
<mml:math id="m395">
<mml:mrow>
<mml:mn>3</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>e</mml:mi>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>24</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">1.53</td>
</tr>
<tr>
<td align="center">Our</td>
<td align="center">
<inline-formula id="inf384">
<mml:math id="m396">
<mml:mrow>
<mml:mn>3</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>8</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf385">
<mml:math id="m397">
<mml:mrow>
<mml:mn>3</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>11</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf386">
<mml:math id="m398">
<mml:mrow>
<mml:mn>7</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">
<inline-formula id="inf387">
<mml:math id="m399">
<mml:mrow>
<mml:mn>6</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>26</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
<td align="center">1.88</td>
</tr>
</tbody>
</table>
</table-wrap>
<fig id="F4" position="float">
<label>FIGURE 4</label>
<caption>
<p>Computation overhead.</p>
</caption>
<graphic xlink:href="fphy-13-1647836-g004.tif">
<alt-text content-type="machine-generated">Bar chart showing computation overhead in milliseconds across six categories labeled as references [42], [43], [44], [45], [46], and &#x22;Our&#x22;. Categories are divided into orange (User), brown (Cloud Server, note spelling error as 'Sever'), blue (Access Device), and yellow (Total). Overheads range from 0 to over 6 milliseconds, with the 'Total' bars being the tallest in most categories.</alt-text>
</graphic>
</fig>
<p>Regarding total execution time, the Our scheme achieves a time of 1.88030, which is only slightly higher than that of [<xref ref-type="bibr" rid="B46">46</xref>] (1.53252) and [<xref ref-type="bibr" rid="B43">43</xref>] (1.87992), but significantly better than other schemes such as [<xref ref-type="bibr" rid="B42">42</xref>] (4.07076) and [<xref ref-type="bibr" rid="B44">44</xref>] (5.59188). This demonstrates that the Our scheme performs excellently in terms of efficiency and can meet high-performance requirements.</p>
<p>Furthermore, in terms of task distribution, the Our scheme maintains a balanced computational load among the user, cloud server, and access device. Specifically, the user side is responsible for <inline-formula id="inf388">
<mml:math id="m400">
<mml:mrow>
<mml:mn>3</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>8</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, the cloud server handles <inline-formula id="inf389">
<mml:math id="m401">
<mml:mrow>
<mml:mn>3</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mrow>
<mml:mi>c</mml:mi>
<mml:mi>m</mml:mi>
</mml:mrow>
</mml:msub>
<mml:mo>&#x2b;</mml:mo>
<mml:mn>10</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>, and the access device takes <inline-formula id="inf390">
<mml:math id="m402">
<mml:mrow>
<mml:mn>7</mml:mn>
<mml:msub>
<mml:mi>T</mml:mi>
<mml:mi>h</mml:mi>
</mml:msub>
</mml:mrow>
</mml:math>
</inline-formula>. Compared to other schemes where one component may bear a disproportionate load, the Our scheme avoids performance bottlenecks, contributing to more stable and scalable system operation.</p>
<p>In summary, our scheme demonstrates strong overall advantages in computational efficiency, execution time, and load distribution, making it well-suited for practical deployment and widespread application.</p>
</sec>
<sec id="s5-3">
<label>5.3</label>
<title>Communication overhead</title>
<p>
<xref ref-type="table" rid="T4">Table 4</xref> and <xref ref-type="fig" rid="F5">Figure 5</xref> present a comparison of the communication overhead between the proposed protocol and five related protocols. For the sake of a fair comparison, the lengths of various parameters are uniformly set as follows: 160 bits for the Chebyshev polynomial, 320 bits for points on the elliptic curve, 160 bits for hash values, 128 bits for random nonces, 32 bits for the identities of the user and the access device node, 32 bits for timestamps, and 128 bits for blocks used in symmetric encryption and decryption. In addition, the communication process in the proposed protocol involves several potential components, including the user terminal, the PUF module embedded in the device, the encryption/decryption unit, the secure communication channel (e.g., TLS/SSL), and the core cloud server with its key management and auditing modules. These components together ensure the reliability, confidentiality, and integrity of message exchanges, forming the foundation for a fair and meaningful comparison of communication overhead.</p>
<table-wrap id="T4" position="float">
<label>TABLE 4</label>
<caption>
<p>Comparison on communication overhead.</p>
</caption>
<table>
<thead valign="top">
<tr>
<th align="center">Scheme</th>
<th align="center">Communication overhead (bits)</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td align="center">[<xref ref-type="bibr" rid="B42">42</xref>]</td>
<td align="center">2,848</td>
</tr>
<tr>
<td align="center">[<xref ref-type="bibr" rid="B43">43</xref>]</td>
<td align="center">
<inline-formula id="inf391">
<mml:math id="m403">
<mml:mrow>
<mml:mn>3</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>232</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
</tr>
<tr>
<td align="center">[<xref ref-type="bibr" rid="B44">44</xref>]</td>
<td align="center">
<inline-formula id="inf392">
<mml:math id="m404">
<mml:mrow>
<mml:mn>2</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>720</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
</tr>
<tr>
<td align="center">[<xref ref-type="bibr" rid="B45">45</xref>]</td>
<td align="center">
<inline-formula id="inf393">
<mml:math id="m405">
<mml:mrow>
<mml:mn>1</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>760</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
</tr>
<tr>
<td align="center">[<xref ref-type="bibr" rid="B46">46</xref>]</td>
<td align="center">
<inline-formula id="inf394">
<mml:math id="m406">
<mml:mrow>
<mml:mn>2</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>816</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
</tr>
<tr>
<td align="center">Our</td>
<td align="center">
<inline-formula id="inf395">
<mml:math id="m407">
<mml:mrow>
<mml:mn>2</mml:mn>
<mml:mo>,</mml:mo>
<mml:mn>144</mml:mn>
</mml:mrow>
</mml:math>
</inline-formula>
</td>
</tr>
</tbody>
</table>
</table-wrap>
<fig id="F5" position="float">
<label>FIGURE 5</label>
<caption>
<p>Communication overhead.</p>
</caption>
<graphic xlink:href="fphy-13-1647836-g005.tif">
<alt-text content-type="machine-generated">Bar chart comparing communication overhead in bits across six categories: [42], [43], [44], [45], [46], and &#x22;Our&#x22;. The values range from 0.5 to 2.0, with [44] having the highest overhead and [43] the lowest.</alt-text>
</graphic>
</fig>
<p>As shown in <xref ref-type="table" rid="T4">Table 4</xref>, the proposed scheme demonstrates a significant advantage in terms of communication cost, achieving a total of 2,144 bits, which is relatively low compared to all the referenced schemes.</p>
<p>Specifically, compared to the highest communication cost in [<xref ref-type="bibr" rid="B43">43</xref>] (3,232 bits), the proposed scheme reduces the overhead by approximately 33.7%. It also achieves reductions of about 24.7% compared to [<xref ref-type="bibr" rid="B42">42</xref>] (2,848 bits), 21.2% compared to [<xref ref-type="bibr" rid="B44">44</xref>] (2,720 bits), and 23.9% compared to [<xref ref-type="bibr" rid="B46">46</xref>] (2,816 bits). Although [<xref ref-type="bibr" rid="B45">45</xref>] has the lowest communication cost (1,760 bits), it likely involves trade-offs in terms of computational complexity, security mechanisms, or functional completeness; otherwise, it would not be outperformed by more efficient schemes.</p>
<p>Overall, the proposed scheme effectively reduces communication overhead while maintaining system security and functional integrity. It achieves a communication cost optimization of approximately 20%&#x2013;35% compared to most existing schemes, making it well-suited for bandwidth- and energy-constrained environments such as the Internet of Things and edge computing.</p>
</sec>
</sec>
<sec sec-type="conclusion" id="s6">
<label>6</label>
<title>Conclusion</title>
<p>This paper presents an anonymous and secure authentication scheme for 6G cloud environments by combining Chebyshev chaotic mapping with the PUF mechanism. The scheme achieves secure identity verification, session key confidentiality, and resistance to common network attacks, while experiments demonstrate significant improvements in authentication efficiency and reductions in computational and communication overhead. Limitations remain regarding large-scale scalability, cross-vendor PUF compatibility, and sensitivity of chaotic parameters, which open meaningful directions for future research. Overall, the scheme offers a promising security solution for high-concurrency 6G cloud systems and provides a foundation for further exploration.</p>
</sec>
</body>
<back>
<sec sec-type="data-availability" id="s7">
<title>Data availability statement</title>
<p>The original contributions presented in the study are included in the article/supplementary material, further inquiries can be directed to the corresponding author.</p>
</sec>
<sec sec-type="author-contributions" id="s8">
<title>Author contributions</title>
<p>SY: Conceptualization, Formal Analysis, Investigation, Project administration, Resources, Validation, Visualization, Writing &#x2013; original draft. ZJ: Data curation, Methodology, Software, Supervision, Writing &#x2013; review and editing.</p>
</sec>
<sec sec-type="COI-statement" id="s10">
<title>Conflict of interest</title>
<p>The authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.</p>
</sec>
<sec sec-type="ai-statement" id="s11">
<title>Generative AI statement</title>
<p>The author(s) declare that no Generative AI was used in the creation of this manuscript.</p>
<p>Any alternative text (alt text) provided alongside figures in this article has been generated by Frontiers with the support of artificial intelligence and reasonable efforts have been made to ensure accuracy, including review by the authors wherever possible. If you identify any issues, please contact us.</p>
</sec>
<sec sec-type="disclaimer" id="s12">
<title>Publisher&#x2019;s note</title>
<p>All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.</p>
</sec>
<fn-group>
<fn fn-type="custom" custom-type="edited-by">
<p>
<bold>Edited by:</bold> <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/101109/overview">Chengyi Xia</ext-link>, Tianjin Polytechnic University, China</p>
</fn>
<fn fn-type="custom" custom-type="reviewed-by">
<p>
<bold>Reviewed by:</bold> <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/2960793/overview">Devishree Naidu</ext-link>, Shri Ramdeobaba College of Engineering and Management, India</p>
<p>
<ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/3123992/overview">Zhang Zhipeng</ext-link>, Tianjin Polytechnic University, China</p>
</fn>
</fn-group>
<ref-list>
<title>References</title>
<ref id="B1">
<label>1.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Chen</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Li</surname>
<given-names>T</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>You</surname>
<given-names>T</given-names>
</name>
<name>
<surname>Lu</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Tiwari</surname>
<given-names>P</given-names>
</name>
<etal/>
</person-group> <article-title>Global-and-local attention-based reinforcement learning for cooperative behaviour control of multiple UAVs</article-title>. <source>IEEE Trans Vehicular Technol</source> (<year>2023</year>) <volume>73</volume>(<issue>3</issue>):<fpage>4194</fpage>&#x2013;<lpage>206</lpage>. <pub-id pub-id-type="doi">10.1109/tvt.2023.3327571</pub-id>
</mixed-citation>
</ref>
<ref id="B2">
<label>2.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Miao</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Ning</surname>
<given-names>X</given-names>
</name>
<name>
<surname>Hong</surname>
<given-names>S</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>L</given-names>
</name>
<name>
<surname>Liu</surname>
<given-names>B</given-names>
</name>
</person-group>. <article-title>Secure and efficient authentication protocol for supply chain systems in artificial intelligence-based internet of things</article-title>. <source>IEEE Internet Things J</source> (<year>2025</year>) <volume>12</volume>:<fpage>39532</fpage>&#x2013;<lpage>42</lpage>. <pub-id pub-id-type="doi">10.1109/jiot.2025.3592401</pub-id>
</mixed-citation>
</ref>
<ref id="B3">
<label>3.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Bai</surname>
<given-names>Z</given-names>
</name>
<name>
<surname>Miao</surname>
<given-names>H</given-names>
</name>
<name>
<surname>Miao</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Xiao</surname>
<given-names>N</given-names>
</name>
<name>
<surname>Sun</surname>
<given-names>X</given-names>
</name>
</person-group>. <article-title>Artificial intelligence-driven cybersecurity applications and challenges</article-title>. <source>Innovative Appl AI</source> (<year>2025</year>) <volume>2</volume>(<issue>2</issue>):<fpage>26</fpage>&#x2013;<lpage>33</lpage>. <pub-id pub-id-type="doi">10.70695/AA1202502A09</pub-id>
</mixed-citation>
</ref>
<ref id="B4">
<label>4.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Farhoudi</surname>
<given-names>M</given-names>
</name>
<name>
<surname>Shokrnezhad</surname>
<given-names>M</given-names>
</name>
<name>
<surname>Taleb</surname>
<given-names>T</given-names>
</name>
<name>
<surname>Li</surname>
<given-names>R</given-names>
</name>
<name>
<surname>Song</surname>
<given-names>J</given-names>
</name>
</person-group>. <article-title>Discovery of 6G services and resources in edge-cloud-continuum</article-title>. <source>IEEE Netw</source> (<year>2024</year>) <volume>39</volume>:<fpage>223</fpage>&#x2013;<lpage>32</lpage>. <pub-id pub-id-type="doi">10.1109/mnet.2024.3438096</pub-id>
</mixed-citation>
</ref>
<ref id="B5">
<label>5.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Chen</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Shu</surname>
<given-names>Q</given-names>
</name>
<name>
<surname>Lu</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>Y</given-names>
</name>
</person-group>. <article-title>QCTF: a quantized communication and transferable fusion framework for multi-agent collaborative perception</article-title>. <source>IEEE Trans Intell Transportation Syst</source> (<year>2025</year>) <volume>26</volume>:<fpage>15013</fpage>&#x2013;<lpage>27</lpage>. <pub-id pub-id-type="doi">10.1109/TITS.2025.3574725</pub-id>
</mixed-citation>
</ref>
<ref id="B6">
<label>6.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Razaque</surname>
<given-names>A</given-names>
</name>
<name>
<surname>Khan</surname>
<given-names>M</given-names>
</name>
<name>
<surname>Yoo</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Alotaibi</surname>
<given-names>A</given-names>
</name>
<name>
<surname>Alshammari</surname>
<given-names>M</given-names>
</name>
<name>
<surname>Almiani</surname>
<given-names>M</given-names>
</name>
</person-group>. <article-title>Blockchain-enabled heterogeneous 6G supported secure vehicular management system over cloud edge computing</article-title>. <source>Internet Things</source> (<year>2024</year>) <volume>25</volume>:<fpage>101115</fpage>. <pub-id pub-id-type="doi">10.1016/j.iot.2024.101115</pub-id>
</mixed-citation>
</ref>
<ref id="B7">
<label>7.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Xiao</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Gao</surname>
<given-names>S</given-names>
</name>
</person-group>. <article-title>5GAKA-LCCO: a secure 5G authentication and key agreement protocol with less communication and computation overhead</article-title>. <source>Information</source> (<year>2022</year>) <volume>13</volume>(<issue>5</issue>):<fpage>257</fpage>. <pub-id pub-id-type="doi">10.3390/info13050257</pub-id>
</mixed-citation>
</ref>
<ref id="B8">
<label>8.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Chen</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Ren</surname>
<given-names>C</given-names>
</name>
<name>
<surname>Hu</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Lu</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Li</surname>
<given-names>Q</given-names>
</name>
<etal/>
</person-group> <article-title>Dual-centralized Q-Network-Based reinforcement learning for cooperative path planning of multiple UAVs</article-title>. <source>IEEE Trans Intell Transportation Syst</source> (<year>2025</year>) <volume>26</volume>:<fpage>13232</fpage>&#x2013;<lpage>46</lpage>. <pub-id pub-id-type="doi">10.1109/TITS.2025.3587392</pub-id>
</mixed-citation>
</ref>
<ref id="B9">
<label>9.</label>
<mixed-citation publication-type="book">
<person-group person-group-type="author">
<name>
<surname>Gupta</surname>
<given-names>DS</given-names>
</name>
<name>
<surname>Parai</surname>
<given-names>K</given-names>
</name>
<name>
<surname>Obaidat</surname>
<given-names>MS</given-names>
</name>
</person-group>. <source>Efficient and secure design of id-3paka protocol using ECC[C]//2021 international conference on computer, information and telecommunication systems (CITS)</source>. <publisher-loc>IEEE</publisher-loc> (<year>2021</year>). p. <fpage>1</fpage>&#x2013;<lpage>5</lpage>.</mixed-citation>
</ref>
<ref id="B10">
<label>10.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Parai</surname>
<given-names>K</given-names>
</name>
<name>
<surname>Gupta</surname>
<given-names>DS</given-names>
</name>
<name>
<surname>Islam</surname>
<given-names>SKH</given-names>
</name>
</person-group>. <article-title>IoT-ID3PAKA: efficient and robust ID-3PAKA protocol for resource-constrained IoT devices</article-title>. <source>IEEE Internet Things J</source> (<year>2023</year>) <volume>11</volume>:<fpage>10304</fpage>&#x2013;<lpage>13</lpage>. <pub-id pub-id-type="doi">10.1109/jiot.2023.3325583</pub-id>
</mixed-citation>
</ref>
<ref id="B11">
<label>11.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Mookherji</surname>
<given-names>S</given-names>
</name>
<name>
<surname>Odelu</surname>
<given-names>V</given-names>
</name>
<name>
<surname>Prasath</surname>
<given-names>R</given-names>
</name>
<name>
<surname>Das</surname>
<given-names>AK</given-names>
</name>
<name>
<surname>Park</surname>
<given-names>Y</given-names>
</name>
</person-group>. <article-title>Fog-based single sign-on authentication protocol for electronic healthcare applications</article-title>. <source>IEEE Internet Things J</source> (<year>2023</year>) <volume>10</volume>:<fpage>10983</fpage>&#x2013;<lpage>96</lpage>. <pub-id pub-id-type="doi">10.1109/jiot.2023.3242903</pub-id>
</mixed-citation>
</ref>
<ref id="B12">
<label>12.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Xiong</surname>
<given-names>L</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>JK</given-names>
</name>
<name>
<surname>Yu</surname>
<given-names>L</given-names>
</name>
<name>
<surname>Xiong</surname>
<given-names>N</given-names>
</name>
<name>
<surname>Wu</surname>
<given-names>H</given-names>
</name>
</person-group>. <article-title>An efficient privacy-preserving access control scheme for cloud computing services</article-title>. <source>IEEE Trans Consumer Electron</source> (<year>2025</year>) <volume>71</volume>:<fpage>6642</fpage>&#x2013;<lpage>58</lpage>. <pub-id pub-id-type="doi">10.1109/tce.2025.3534833</pub-id>
</mixed-citation>
</ref>
<ref id="B13">
<label>13.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Soni</surname>
<given-names>P</given-names>
</name>
<name>
<surname>Pradhan</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Pal</surname>
<given-names>AK</given-names>
</name>
<name>
<surname>Islam</surname>
<given-names>SH</given-names>
</name>
</person-group>. <article-title>Cybersecurity attack-resilience authentication mechanism for intelligent healthcare system</article-title>. <source>IEEE Trans Ind Inform</source> (<year>2022</year>) <volume>19</volume>(<issue>1</issue>):<fpage>830</fpage>&#x2013;<lpage>40</lpage>. <pub-id pub-id-type="doi">10.1109/tii.2022.3179429</pub-id>
</mixed-citation>
</ref>
<ref id="B14">
<label>14.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Qiu</surname>
<given-names>S</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>D</given-names>
</name>
<name>
<surname>Xu</surname>
<given-names>G</given-names>
</name>
<name>
<surname>Kumari</surname>
<given-names>S</given-names>
</name>
</person-group>. <article-title>Practical and provably secure three-factor authentication protocol based on extended chaotic-maps for Mobile lightweight devices</article-title>. <source>IEEE Trans Dependable Secure Comput</source> (<year>2020</year>) <volume>19</volume>(<issue>2</issue>):<fpage>1</fpage>&#x2013;<lpage>1351</lpage>. <pub-id pub-id-type="doi">10.1109/tdsc.2020.3022797</pub-id>
</mixed-citation>
</ref>
<ref id="B15">
<label>15.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Lin</surname>
<given-names>TW</given-names>
</name>
<name>
<surname>Hsu</surname>
<given-names>CL</given-names>
</name>
<name>
<surname>Le</surname>
<given-names>TV</given-names>
</name>
<name>
<surname>Lu</surname>
<given-names>CF</given-names>
</name>
<name>
<surname>Huang</surname>
<given-names>BY</given-names>
</name>
</person-group>. <article-title>A Smartcard-Based user-controlled single sign-on for privacy preservation in 5G-IoT telemedicine systems</article-title>. <source>Sensors</source> (<year>2021</year>) <volume>21</volume>(<issue>8</issue>):<fpage>2880</fpage>. <pub-id pub-id-type="doi">10.3390/s21082880</pub-id>
<pub-id pub-id-type="pmid">33924024</pub-id>
</mixed-citation>
</ref>
<ref id="B16">
<label>16.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Alzahrani</surname>
<given-names>BA</given-names>
</name>
<name>
<surname>Irshad</surname>
<given-names>A</given-names>
</name>
<name>
<surname>Albeshri</surname>
<given-names>A</given-names>
</name>
<name>
<surname>Alsubhi</surname>
<given-names>K</given-names>
</name>
</person-group>. <article-title>A provably secure and lightweight patient-healthcare authentication protocol in wireless body area networks</article-title>. <source>Wireless Personal Commun</source> (<year>2021</year>) <volume>117</volume>(<issue>1</issue>):<fpage>47</fpage>&#x2013;<lpage>69</lpage>. <pub-id pub-id-type="doi">10.1007/s11277-020-07237-x</pub-id>
</mixed-citation>
</ref>
<ref id="B17">
<label>17.</label>
<mixed-citation publication-type="book">
<person-group person-group-type="author">
<name>
<surname>Nyangaresi</surname>
<given-names>VO</given-names>
</name>
</person-group>. <source>Provably secure pseudonyms based authentication protocol for wearable ubiquitous computing Environment[C]//2022 international conference on inventive computation technologies (ICICT)</source>. <publisher-loc>IEEE</publisher-loc> (<year>2022</year>). p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation>
</ref>
<ref id="B18">
<label>18.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Xie</surname>
<given-names>Q</given-names>
</name>
<name>
<surname>Liu</surname>
<given-names>D</given-names>
</name>
<name>
<surname>Ding</surname>
<given-names>Z</given-names>
</name>
<name>
<surname>Tan</surname>
<given-names>X</given-names>
</name>
<name>
<surname>Han</surname>
<given-names>L</given-names>
</name>
</person-group>. <article-title>Provably secure and lightweight patient monitoring protocol for wireless body area network in IoHT</article-title>. <source>J Healthc Eng</source> (<year>2023</year>) <volume>2023</volume>(<issue>1</issue>):<fpage>4845850</fpage>. <pub-id pub-id-type="doi">10.1155/2023/4845850</pub-id>
<pub-id pub-id-type="pmid">36814548</pub-id>
</mixed-citation>
</ref>
<ref id="B19">
<label>19.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Deebak</surname>
<given-names>BD</given-names>
</name>
<name>
<surname>Hwang</surname>
<given-names>SO</given-names>
</name>
</person-group>. <article-title>A cloud-assisted medical cyber-physical system using a privacy-preserving key agreement framework and a chebyshev chaotic map</article-title>. <source>IEEE Syst J</source> (<year>2023</year>) <volume>17</volume>(<issue>4</issue>):<fpage>5543</fpage>&#x2013;<lpage>54</lpage>. <pub-id pub-id-type="doi">10.1109/JSYST.2023.3303460</pub-id>
</mixed-citation>
</ref>
<ref id="B20">
<label>20.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Tu</surname>
<given-names>S</given-names>
</name>
<name>
<surname>Badshah</surname>
<given-names>A</given-names>
</name>
<name>
<surname>Alasmary</surname>
<given-names>H</given-names>
</name>
</person-group>. <article-title>EAKE-WC: efficient and anonymous AuthenticatedKey exchange scheme for wearable computing</article-title>. <source>IEEE Trans Mobile Computing</source> (<year>2023</year>) <volume>1</volume>:<fpage>1</fpage>&#x2013;<lpage>12</lpage>. <pub-id pub-id-type="doi">10.1109/TMC.2023.3297854</pub-id>
</mixed-citation>
</ref>
<ref id="B21">
<label>21.</label>
<mixed-citation publication-type="book">
<person-group person-group-type="author">
<name>
<surname>Edwards</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Aparicio-Navarro</surname>
<given-names>FJ</given-names>
</name>
<name>
<surname>Maglaras</surname>
<given-names>L</given-names>
</name>
</person-group>. <source>FFDA: a novel four-factor distributed authentication Mechanism[C]//2022 IEEE international conference on cyber security and resilience (CSR)</source>. <publisher-loc>Rhodes, Greece</publisher-loc>: <publisher-name>IEEE</publisher-name> (<year>2022</year>). p. <fpage>376</fpage>&#x2013;<lpage>81</lpage>.</mixed-citation>
</ref>
<ref id="B22">
<label>22.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Lee</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Oh</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Kwon</surname>
<given-names>D</given-names>
</name>
<name>
<surname>Kim</surname>
<given-names>M</given-names>
</name>
<name>
<surname>Yu</surname>
<given-names>S</given-names>
</name>
<name>
<surname>Jho</surname>
<given-names>NS</given-names>
</name>
<etal/>
</person-group> <article-title>PUFTAP-IoT: PUF-based three-factor authentication protocol in IoT environment focused on sensing devices</article-title>. <source>Sensors</source> (<year>2022</year>) <volume>22</volume>(<issue>18</issue>):<fpage>7075</fpage>. <pub-id pub-id-type="doi">10.3390/s22187075</pub-id>
<pub-id pub-id-type="pmid">36146423</pub-id>
</mixed-citation>
</ref>
<ref id="B23">
<label>23.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Ghafouri Mirsaraei</surname>
<given-names>A</given-names>
</name>
<name>
<surname>Barati</surname>
<given-names>A</given-names>
</name>
<name>
<surname>Barati</surname>
<given-names>H</given-names>
</name>
</person-group>. <article-title>A secure three-factor authentication scheme for IoT environments</article-title>. <source>J Parallel Distributed Comput</source> (<year>2022</year>) <volume>169</volume>:<fpage>87</fpage>&#x2013;<lpage>105</lpage>. <pub-id pub-id-type="doi">10.1016/j.jpdc.2022.06.011</pub-id>
</mixed-citation>
</ref>
<ref id="B24">
<label>24.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zhang</surname>
<given-names>L</given-names>
</name>
<name>
<surname>Zhu</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Ren</surname>
<given-names>W</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Choo</surname>
<given-names>KKR</given-names>
</name>
</person-group>. <article-title>Privacy-preserving fast three-factor authentication and key agreement for IoT-Based E-Health systems</article-title>. <source>IEEE Trans Serv Comput</source> (<year>2023</year>) <volume>16</volume>(<issue>2</issue>):<fpage>1324</fpage>&#x2013;<lpage>33</lpage>. <pub-id pub-id-type="doi">10.1109/tsc.2022.3149940</pub-id>
</mixed-citation>
</ref>
<ref id="B25">
<label>25.</label>
<mixed-citation publication-type="book">
<person-group person-group-type="author">
<name>
<surname>Ghose</surname>
<given-names>N</given-names>
</name>
<name>
<surname>Gupta</surname>
<given-names>K</given-names>
</name>
<name>
<surname>Lazos</surname>
<given-names>L</given-names>
</name>
</person-group>. <source>ZITA: zero-interaction two-factor authentication using contact traces and In-band proximity verification</source>. <publisher-name>IEEE Transactions on Mobile Computing</publisher-name> (<year>2023</year>). p. <fpage>1</fpage>&#x2013;<lpage>16</lpage>.</mixed-citation>
</ref>
<ref id="B26">
<label>26.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Ahmad</surname>
<given-names>MO</given-names>
</name>
<name>
<surname>Tripathi</surname>
<given-names>G</given-names>
</name>
<name>
<surname>Siddiqui</surname>
<given-names>F</given-names>
</name>
<name>
<surname>Alam</surname>
<given-names>MA</given-names>
</name>
<name>
<surname>Ahad</surname>
<given-names>MA</given-names>
</name>
<name>
<surname>Akhtar</surname>
<given-names>MM</given-names>
</name>
<etal/>
</person-group> <article-title>BAuth-ZKP&#x2014;a blockchain-based multi-factor authentication mechanism for securing smart cities</article-title>. <source>Sensors</source> (<year>2023</year>) <volume>23</volume>(<issue>5</issue>):<fpage>2757</fpage>. <pub-id pub-id-type="doi">10.3390/s23052757</pub-id>
<pub-id pub-id-type="pmid">36904955</pub-id>
</mixed-citation>
</ref>
<ref id="B27">
<label>27.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Braeken</surname>
<given-names>A</given-names>
</name>
</person-group>. <article-title>Highly efficient bidirectional multifactor authentication and key agreement for real-time access to sensor data</article-title>. <source>IEEE Internet Things J</source> (<year>2023</year>) <volume>10</volume>(<issue>23</issue>):<fpage>21089</fpage>&#x2013;<lpage>99</lpage>. <pub-id pub-id-type="doi">10.1109/jiot.2023.3284501</pub-id>
</mixed-citation>
</ref>
<ref id="B28">
<label>28.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Miao</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>Z</given-names>
</name>
<name>
<surname>Wu</surname>
<given-names>Z</given-names>
</name>
<name>
<surname>Ning</surname>
<given-names>X</given-names>
</name>
<name>
<surname>Tiwari</surname>
<given-names>P</given-names>
</name>
</person-group>. <article-title>A blockchain-enabled privacy-preserving authentication management protocol for internet of medical things</article-title>. <source>Expert Syst Appl</source> (<year>2024</year>) <volume>237</volume>:<fpage>121329</fpage>. <pub-id pub-id-type="doi">10.1016/j.eswa.2023.121329</pub-id>
</mixed-citation>
</ref>
<ref id="B29">
<label>29.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zhang</surname>
<given-names>Z</given-names>
</name>
<name>
<surname>Huang</surname>
<given-names>W</given-names>
</name>
<name>
<surname>Huang</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Liao</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Zhou</surname>
<given-names>S</given-names>
</name>
</person-group>. <article-title>A domain isolated tripartite authenticated key agreement protocol with dynamic revocation and online public identity updating for IIoT</article-title>. <source>IEEE Internet Things J</source> (<year>2024</year>) <volume>11</volume>:<fpage>15616</fpage>&#x2013;<lpage>32</lpage>. <pub-id pub-id-type="doi">10.1109/jiot.2023.3349005</pub-id>
</mixed-citation>
</ref>
<ref id="B30">
<label>30.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Bernard</surname>
<given-names>EB</given-names>
</name>
<name>
<surname>Chen</surname>
<given-names>C</given-names>
</name>
<name>
<surname>Shirui</surname>
<given-names>W</given-names>
</name>
<name>
<surname>Guo</surname>
<given-names>H</given-names>
</name>
<name>
<surname>Liu</surname>
<given-names>J</given-names>
</name>
</person-group>. <article-title>A secure mutual authentication protocol based on visual cryptography technique for IoT-Cloud</article-title>. <source>Chin J Electron</source> (<year>2024</year>) <volume>33</volume>(<issue>1</issue>):<fpage>43</fpage>&#x2013;<lpage>57</lpage>. <pub-id pub-id-type="doi">10.23919/cje.2022.00.339</pub-id>
</mixed-citation>
</ref>
<ref id="B31">
<label>31.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Pappu</surname>
<given-names>R</given-names>
</name>
<name>
<surname>Ravikanth</surname>
<given-names>B</given-names>
</name>
<name>
<surname>Recht</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Gershenfeld</surname>
<given-names>N</given-names>
</name>
</person-group>. <article-title>Physical one-way functions</article-title>. <source>Science</source> (<year>2002</year>) <volume>297</volume>(<issue>5589</issue>):<fpage>2026</fpage>&#x2013;<lpage>30</lpage>. <pub-id pub-id-type="doi">10.1126/science.1074376</pub-id>
<pub-id pub-id-type="pmid">12242435</pub-id>
</mixed-citation>
</ref>
<ref id="B32">
<label>32.</label>
<mixed-citation publication-type="book">
<person-group person-group-type="author">
<name>
<surname>Min</surname>
<given-names>Z</given-names>
</name>
<name>
<surname>Yao</surname>
<given-names>X</given-names>
</name>
<name>
<surname>Hong</surname>
<given-names>L</given-names>
</name>
</person-group>. <source>Physical unclonable function based authentication protocol for unit IoT and ubiquitous IoT[C]//international conference on identification</source>. <publisher-name>IEEE Computer Society</publisher-name> (<year>2016</year>). p. <fpage>179 184</fpage>.</mixed-citation>
</ref>
<ref id="B33">
<label>33.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Aman</surname>
<given-names>MN</given-names>
</name>
<name>
<surname>Chua</surname>
<given-names>KC</given-names>
</name>
<name>
<surname>Sikdar</surname>
<given-names>B</given-names>
</name>
</person-group>. <article-title>Mutual authentication in IoT systems using physical unclonable functions</article-title>. <source>IEEE Internet Things J</source> (<year>2017</year>) <volume>4</volume>(<issue>5</issue>):<fpage>1327</fpage>&#x2013;<lpage>40</lpage>. <pub-id pub-id-type="doi">10.1109/jiot.2017.2703088</pub-id>
</mixed-citation>
</ref>
<ref id="B34">
<label>34.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Shah</surname>
<given-names>T</given-names>
</name>
<name>
<surname>Venkatesan</surname>
<given-names>S</given-names>
</name>
</person-group>. <article-title>Authentication of IoT device and IoT server using secure vaults</article-title>, <volume>819</volume> (<year>2018</year>). p. <fpage>824</fpage>.</mixed-citation>
</ref>
<ref id="B35">
<label>35.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zhu</surname>
<given-names>F</given-names>
</name>
<name>
<surname>Li</surname>
<given-names>P</given-names>
</name>
<name>
<surname>Xu</surname>
<given-names>H</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>R</given-names>
</name>
</person-group>. <article-title>A lightweight RFID mutual authentication protocol with PUF</article-title>. <source>Sensors</source> (<year>2019</year>) <volume>19</volume>(<issue>13</issue>):<fpage>2957</fpage>&#x2013;<lpage>78</lpage>. <pub-id pub-id-type="doi">10.3390/s19132957</pub-id>
<pub-id pub-id-type="pmid">31277487</pub-id>
</mixed-citation>
</ref>
<ref id="B36">
<label>36.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Mo</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Hu</surname>
<given-names>Z</given-names>
</name>
<name>
<surname>Shen</surname>
<given-names>W</given-names>
</name>
</person-group>. <article-title>A provably secure three-factor authentication protocol based on chebyshev chaotic mapping for wireless sensor network</article-title>. <source>IEEE Access</source> (<year>2022</year>) <volume>10</volume>:<fpage>12137</fpage>&#x2013;<lpage>52</lpage>. <pub-id pub-id-type="doi">10.1109/access.2022.3146393</pub-id>
</mixed-citation>
</ref>
<ref id="B37">
<label>37.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Truong</surname>
<given-names>TT</given-names>
</name>
<name>
<surname>Tran</surname>
<given-names>MT</given-names>
</name>
<name>
<surname>Duong</surname>
<given-names>AD</given-names>
</name>
</person-group>. <article-title>Improved Chebyshev polynomials&#x2010;based authentication scheme in client&#x2010;server environment</article-title>. <source>Security Commun Networks</source> (<year>2019</year>) <volume>2019</volume>(<issue>1</issue>):<fpage>1</fpage>&#x2013;<lpage>11</lpage>. <pub-id pub-id-type="doi">10.1155/2019/4250743</pub-id>
</mixed-citation>
</ref>
<ref id="B38">
<label>38.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>He</surname>
<given-names>K</given-names>
</name>
<name>
<surname>Ren</surname>
<given-names>Z</given-names>
</name>
</person-group>. <article-title>A new three-factor authentication scheme using Chebyshev chaotic map for peer-to-peer industrial internet of things</article-title>. <source>Computer Networks</source> (<year>2024</year>) <volume>247</volume>:<fpage>110450</fpage>. <pub-id pub-id-type="doi">10.1016/j.comnet.2024.110450</pub-id>
</mixed-citation>
</ref>
<ref id="B39">
<label>39.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Kumar</surname>
<given-names>N</given-names>
</name>
<name>
<surname>Ali</surname>
<given-names>R</given-names>
</name>
</person-group>. <article-title>Blockchain-enabled authentication framework for maritime transportation system empowered by 6G-IoT</article-title>. <source>Comput Networks</source> (<year>2024</year>) <volume>244</volume>:<fpage>110353</fpage>. <pub-id pub-id-type="doi">10.1016/j.comnet.2024.110353</pub-id>
</mixed-citation>
</ref>
<ref id="B40">
<label>40.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Yuan</surname>
<given-names>M</given-names>
</name>
<name>
<surname>Tan</surname>
<given-names>H</given-names>
</name>
<name>
<surname>Zheng</surname>
<given-names>W</given-names>
</name>
<name>
<surname>Vijayakumar</surname>
<given-names>P</given-names>
</name>
<name>
<surname>Alqahtani</surname>
<given-names>F</given-names>
</name>
<name>
<surname>Tolba</surname>
<given-names>A</given-names>
</name>
</person-group>. <article-title>A robust ECC-based authentication and key agreement protocol for 6G-based smart home environments</article-title>. <source>IEEE Internet Things J</source> (<year>2024</year>) <volume>11</volume>(<issue>18</issue>):<fpage>29615</fpage>&#x2013;<lpage>27</lpage>. <pub-id pub-id-type="doi">10.1109/jiot.2024.3392498</pub-id>
</mixed-citation>
</ref>
<ref id="B41">
<label>41.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Kumar</surname>
<given-names>N</given-names>
</name>
<name>
<surname>Ali</surname>
<given-names>R</given-names>
</name>
</person-group>. <article-title>A smart contract-based 6G-enabled authentication scheme for securing internet of nano medical things network</article-title>. <source>Ad Hoc Networks</source> (<year>2024</year>) <volume>163</volume>:<fpage>103606</fpage>. <pub-id pub-id-type="doi">10.1016/j.adhoc.2024.103606</pub-id>
</mixed-citation>
</ref>
<ref id="B42">
<label>42.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zhao</surname>
<given-names>X</given-names>
</name>
<name>
<surname>Li</surname>
<given-names>D</given-names>
</name>
<name>
<surname>Li</surname>
<given-names>H</given-names>
</name>
</person-group>. <article-title>Practical three-factor authentication protocol based on elliptic curve cryptography for industrial internet of things</article-title>. <source>Sensors</source> (<year>2022</year>) <volume>22</volume>(<issue>19</issue>):<fpage>7510</fpage>. <pub-id pub-id-type="doi">10.3390/s22197510</pub-id>
<pub-id pub-id-type="pmid">36236609</pub-id>
</mixed-citation>
</ref>
<ref id="B43">
<label>43.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Irshad</surname>
<given-names>A</given-names>
</name>
<name>
<surname>Chaudhry</surname>
<given-names>SA</given-names>
</name>
<name>
<surname>Xie</surname>
<given-names>Q</given-names>
</name>
<name>
<surname>Li</surname>
<given-names>X</given-names>
</name>
<name>
<surname>Farash</surname>
<given-names>MS</given-names>
</name>
<name>
<surname>Kumari</surname>
<given-names>S</given-names>
</name>
<etal/>
</person-group> <article-title>An enhanced and provably secure chaotic map-based authenticated key agreement in multi-server architecture</article-title>. <source>Arabian J Sci Eng</source> (<year>2018</year>) <volume>43</volume>:<fpage>811</fpage>&#x2013;<lpage>28</lpage>. <pub-id pub-id-type="doi">10.1007/s13369-017-2764-z</pub-id>
</mixed-citation>
</ref>
<ref id="B44">
<label>44.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Thakur</surname>
<given-names>G</given-names>
</name>
<name>
<surname>Prajapat</surname>
<given-names>S</given-names>
</name>
<name>
<surname>Kumar</surname>
<given-names>P</given-names>
</name>
<name>
<surname>Chen</surname>
<given-names>CM</given-names>
</name>
</person-group>. <article-title>A privacy-preserving three-factor authentication system for IoT-enabled wireless sensor networks</article-title>. <source>J Syst Architecture</source> (<year>2024</year>) <volume>154</volume>:<fpage>103245</fpage>. <pub-id pub-id-type="doi">10.1016/j.sysarc.2024.103245</pub-id>
</mixed-citation>
</ref>
<ref id="B45">
<label>45.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Li</surname>
<given-names>F</given-names>
</name>
<name>
<surname>Yu</surname>
<given-names>X</given-names>
</name>
<name>
<surname>Cui</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Yu</surname>
<given-names>S</given-names>
</name>
<name>
<surname>Sun</surname>
<given-names>Y</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>Y</given-names>
</name>
<etal/>
</person-group> <article-title>An anonymous authentication and key agreement protocol in smart living</article-title>. <source>Comput Commun</source> (<year>2022</year>) <volume>186</volume>:<fpage>110</fpage>&#x2013;<lpage>20</lpage>. <pub-id pub-id-type="doi">10.1016/j.comcom.2022.01.019</pub-id>
</mixed-citation>
</ref>
<ref id="B46">
<label>46.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Abdi Nasib Far</surname>
<given-names>H</given-names>
</name>
<name>
<surname>Bayat</surname>
<given-names>M</given-names>
</name>
<name>
<surname>Kumar Das</surname>
<given-names>A</given-names>
</name>
<name>
<surname>Fotouhi</surname>
<given-names>M</given-names>
</name>
<name>
<surname>Pournaghi</surname>
<given-names>SM</given-names>
</name>
<name>
<surname>Doostari</surname>
<given-names>MA</given-names>
</name>
</person-group>. <article-title>LAPTAS: lightweight anonymous privacy-preserving three-factor authentication scheme for WSN-based IIoT</article-title>. <source>Wireless Networks</source> (<year>2021</year>) <volume>27</volume>(<issue>2</issue>):<fpage>1389</fpage>&#x2013;<lpage>412</lpage>. <pub-id pub-id-type="doi">10.1007/s11276-020-02523-9</pub-id>
</mixed-citation>
</ref>
<ref id="B47">
<label>47.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Cui</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Yu</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Zhong</surname>
<given-names>H</given-names>
</name>
<name>
<surname>Wei</surname>
<given-names>L</given-names>
</name>
<name>
<surname>Liu</surname>
<given-names>L</given-names>
</name>
</person-group>. <article-title>Chaotic map-based authentication scheme using physical unclonable function for internet of autonomous vehicle</article-title>. <source>IEEE Trans Intell Transportation Syst</source> (<year>2022</year>) <volume>24</volume>(<issue>3</issue>):<fpage>3167</fpage>&#x2013;<lpage>81</lpage>. <pub-id pub-id-type="doi">10.1109/tits.2022.3227949</pub-id>
</mixed-citation>
</ref>
<ref id="B48">
<label>48.</label>
<mixed-citation publication-type="journal">
<person-group person-group-type="author">
<name>
<surname>Jiang</surname>
<given-names>Q</given-names>
</name>
<name>
<surname>Zhang</surname>
<given-names>N</given-names>
</name>
<name>
<surname>Ni</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Ma</surname>
<given-names>J</given-names>
</name>
<name>
<surname>Ma</surname>
<given-names>X</given-names>
</name>
<name>
<surname>Choo</surname>
<given-names>KKR</given-names>
</name>
</person-group>. <article-title>Unified biometric privacy preserving three-factor authentication and key agreement for cloud-assisted autonomous vehicles</article-title>. <source>IEEE Trans Vehicular Technol</source> (<year>2020</year>) <volume>69</volume>(<issue>9</issue>):<fpage>9390</fpage>&#x2013;<lpage>401</lpage>. <pub-id pub-id-type="doi">10.1109/tvt.2020.2971254</pub-id>
</mixed-citation>
</ref>
</ref-list>
</back>
</article>