SGX-Based Efficient Three-Factor Authentication Scheme with Online Registration for Industrial Internet of Things
Abstract
1. Introduction
- We design an efficient three-factor authentication scheme with online registration for IIoT environments. The scheme leverages the security features of Intel SGX to protect the master key and to realize secure online registration. Moreover, the registration parameters are cleared immediately after use at the end of the registration phase, so they are not retained for later reuse, thereby reducing information leakage.
- We design a faster dynamic authentication credential update mechanism that allows each communicating party to independently refresh its temporary identity credentials. Combined with SGX, this mechanism enables dynamic anonymous authentication and effectively resists privileged user attacks.
- We evaluate the security of the proposed scheme using ProVerif-based verification and informal security analysis. Finally, we demonstrate practicality and efficiency via NS-3 simulations and comparative performance evaluation.
2. Related Work
3. Network Model
3.1. Authentication Model
3.2. Threat Model
- Full control of public channels. can eavesdrop on, intercept, modify, replay, and drop messages transmitted over public channels.
- Device compromise. may obtain the contents of a stolen smartcard via side-channel extraction. Similarly, ISDs may be physically captured, allowing to extract stored parameters.
- Insider adversary. may also be an insider attempting to abuse granted privileges.
- SGX trust boundary. We assume that can completely compromise the untrusted software environment on the gateway side, including the ability to inspect, alter, and replay any information stored in untrusted memory. According to the conventional SGX threat model, plaintext secrets held within enclave-protected memory cannot be directly accessed from outside the enclave boundary [15]. In our scheme, the authentication master key X, together with all intermediate values computed from X, is processed exclusively within enclave-resident execution. Although the untrusted host may observe the input parameters passed to enclave invocations and any non-sensitive outputs returned by the enclave, it cannot directly access the enclave’s internal state. Nevertheless, SGX isolation alone does not eliminate the risk of microarchitectural side-channel leakage, including attacks based on caches, page faults, and speculative execution.
3.3. Intel SGX
4. Proposed Scheme
4.1. Initialization Phase
4.2. User Online Registration Phase
4.3. Sensing Device Online Registration Phase
4.4. Login Phase
4.5. Authentication and Key Agreement Phase

4.6. Dynamic Credential Update Phase
4.7. Password Update Phase
4.8. Smartcard Revocation Phase
4.9. Dynamic Sensing Device Addition Phase
5. Security Analysis
5.1. Formal Security Analysis
ProVerif Simulation
5.2. Informal Security Analysis
5.2.1. Forward Security
5.2.2. Privileged User Attack
5.2.3. Side-Channel Attack
5.2.4. Offline Guessing Attack
5.2.5. Online Guessing Attack
- The adversary can get , from , get from , get from , and get from to compute the session key.
- When the adversary wants to obtain or , the adversary must get , , and . However, the information is transmitted only in hashed form. As a result, the adversary cannot simultaneously recover two unknown parameters through a guessing attack.
5.2.6. Tracking Attack
5.2.7. Replay Attack
5.2.8. Man-in-the-Middle Attack
5.2.9. Sensing Device Capture Attack
5.2.10. Security Comparison
6. Performance Analysis
6.1. Analysis Basis
6.2. Computation Overhead
6.3. Communication Overhead
6.4. NS-3 Simulation
6.4.1. End-to-End Delay
6.4.2. Network Throughput
7. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Wu, Y.; Dai, H.N.; Wang, H.; Xiong, Z.; Guo, S. A survey of intelligent network slicing management for industrial IoT: Integrated approaches for smart transportation, smart energy, and smart factory. IEEE Commun. Surv. Tutor. 2022, 24, 1175–1211. [Google Scholar] [CrossRef]
- Liang, W.; Xie, S.; Zhang, D.; Li, X.; Li, K.C. A mutual security authentication method for RFID-PUF circuit based on deep learning. ACM Trans. Internet Technol. (TOIT) 2021, 22, 1–20. [Google Scholar] [CrossRef]
- Rafique, F.; Obaidat, M.S.; Mahmood, K.; Ayub, M.F.; Ferzund, J.; Chaudhry, S.A. An efficient and provably secure certificateless protocol for industrial Internet of Things. IEEE Trans. Ind. Inform. 2022, 18, 8039–8046. [Google Scholar] [CrossRef]
- Yu, K.; Tan, L.; Aloqaily, M.; Yang, H.; Jararweh, Y. Blockchain-enhanced data sharing with traceable and direct revocation in IIoT. IEEE Trans. Ind. Inform. 2021, 17, 7669–7678. [Google Scholar] [CrossRef]
- Humayed, A.; Lin, J.; Li, F.; Luo, B. Cyber-physical systems security—A survey. IEEE Internet Things J. 2017, 4, 1802–1831. [Google Scholar] [CrossRef]
- Musleh, A.S.; Chen, G.; Dong, Z.Y. A survey on the detection algorithms for false data injection attacks in smart grids. IEEE Trans. Smart Grid 2019, 11, 2218–2234. [Google Scholar] [CrossRef]
- Angle, M.G.; Madnick, S.; Kirtley, J.L.; Khan, S. Identifying and anticipating cyberattacks that could cause physical damage to industrial control systems. IEEE Power Energy Technol. Syst. J. 2019, 6, 172–182. [Google Scholar] [CrossRef]
- Srinivas, J.; Das, A.K.; Wazid, M.; Kumar, N. Anonymous lightweight chaotic map-based authenticated key agreement protocol for industrial Internet of Things. IEEE Trans. Dependable Secur. Comput. 2018, 17, 1133–1146. [Google Scholar] [CrossRef]
- Tanveer, M.; Abbas, G.; Abbas, Z.H.; Bilal, M.; Mukherjee, A.; Kwak, K.S. LAKE-6SH: Lightweight user authenticated key exchange for 6LoWPAN-based smart homes. IEEE Internet Things J. 2021, 9, 2578–2591. [Google Scholar] [CrossRef]
- Ding, X.; Wang, X.; Xie, Y.; Li, F. A lightweight anonymous authentication protocol for resource-constrained devices in Internet of Things. IEEE Internet Things J. 2021, 9, 1818–1829. [Google Scholar] [CrossRef]
- Alzahrani, B.A.; Mahmood, K. Provable privacy preserving authentication solution for internet of things environment. IEEE Access 2021, 9, 82857–82865. [Google Scholar] [CrossRef]
- Cetintav, I.; Sandikkaya, M.T. A review of lightweight IoT authentication protocols from the perspective of security requirements, computation, communication, and hardware costs. IEEE Access 2025, 13, 37703–37723. [Google Scholar] [CrossRef]
- Masud, M.; Gaba, G.S.; Choudhary, K.; Hossain, M.S.; Alhamid, M.F.; Muhammad, G. Lightweight and anonymity-preserving user authentication scheme for IoT-based healthcare. IEEE Internet Things J. 2021, 9, 2649–2656. [Google Scholar] [CrossRef]
- Hadlington, L.; Popovac, M.; Janicke, H.; Yevseyeva, I.; Jones, K. Exploring the role of work identity and work locus of control in information security awareness. Comput. Secur. 2019, 81, 41–48. [Google Scholar] [CrossRef]
- Liu, X.; Guo, Z.; Ma, J.; Song, Y. A secure authentication scheme for wireless sensor networks based on DAC and Intel SGX. IEEE Internet Things J. 2021, 9, 3533–3547. [Google Scholar] [CrossRef]
- Fei, S.; Yan, Z.; Ding, W.; Xie, H. Security vulnerabilities of SGX and countermeasures: A survey. ACM Comput. Surv. (CSUR) 2021, 54, 1–36. [Google Scholar] [CrossRef]
- Tsai, J.L.; Lo, N.W. A privacy-aware authentication scheme for distributed mobile cloud computing services. IEEE Syst. J. 2015, 9, 805–815. [Google Scholar] [CrossRef]
- Amin, R.; Islam, S.H.; Biswas, G.P.; Khan, M.K.; Leng, L.; Kumar, N. Design of an anonymity-preserving three-factor authenticated key exchange protocol for wireless sensor networks. Comput. Netw. 2016, 101, 42–62. [Google Scholar]
- Jiang, Q.; Zeadally, S.; Ma, J.; He, D. Lightweight three-factor authentication and key agreement protocol for internet-integrated wireless sensor networks. IEEE Access 2017, 5, 3376–3392. [Google Scholar]
- Wang, C.; Yuan, Y.; Jiang, S. P3ASC: Privacy-Preserving Pseudonym and Attribute-Based Signcryption Scheme for Cloud-Based Mobile Healthcare System. In Proceedings of the International Conference on Information and Communications Security; Springer: Berlin/Heidelberg, Germany, 2017; pp. 399–411. [Google Scholar]
- Gope, P.; Das, A.K.; Kumar, N.; Cheng, Y. Lightweight and physically secure anonymous mutual authentication protocol for real-time data access in industrial wireless sensor networks. IEEE Trans. Ind. Inform. 2019, 15, 4957–4968. [Google Scholar] [CrossRef]
- Lee, T.F.; Chen, M. Lightweight identity-based group key agreements using extended chaotic maps for wireless sensor networks. IEEE Sens. J. 2019, 19, 10910–10916. [Google Scholar] [CrossRef]
- Turkanović, M.; Brumen, B.; Hölbl, M. A novel user authentication and key agreement scheme for heterogeneous ad hoc wireless sensor networks, based on the Internet of Things notion. Ad Hoc Netw. 2014, 20, 96–112. [Google Scholar] [CrossRef]
- Tai, W.L.; Chang, Y.F.; Li, W.H. An IoT notion–based authentication and key agreement scheme ensuring user anonymity for heterogeneous ad hoc wireless sensor networks. J. Inf. Secur. Appl. 2017, 34, 133–141. [Google Scholar] [CrossRef]
- Esfahani, A.; Mantas, G.; Matischek, R.; Saghezchi, F.B.; Rodriguez, J.; Bicaku, A.; Maksuti, S.; Tauber, M.G.; Schmittner, C.; Bastos, J. A lightweight authentication mechanism for M2M communications in industrial IoT environment. IEEE Internet Things J. 2017, 6, 288–296. [Google Scholar] [CrossRef]
- Xue, K.; Hong, P.; Ma, C. A lightweight dynamic pseudonym identity based authentication and key agreement protocol without verification tables for multi-server architecture. J. Comput. Syst. Sci. 2014, 80, 195–206. [Google Scholar] [CrossRef]
- Chuang, M.C.; Chen, M.C. An anonymous multi-server authenticated key agreement scheme based on trust computing using smart cards and biometrics. Expert Syst. Appl. 2014, 41, 1411–1418. [Google Scholar] [CrossRef]
- Chang, Y.; Zhang, S.; Yan, L.; Han, G.; Song, H.; Zhang, Y.; Li, X.; Wang, Q. A Quantum Authorization Management Protocol Based on EPR-Pairs. Comput. Mater. Contin. 2019, 59, 1005–1014. [Google Scholar] [CrossRef]
- Jia, X.; He, D.; Kumar, N.; Choo, K.K.R. A provably secure and efficient identity-based anonymous authentication scheme for mobile edge computing. IEEE Syst. J. 2019, 14, 560–571. [Google Scholar] [CrossRef]
- Sutrala, A.K.; Bagga, P.; Das, A.K.; Kumar, N.; Rodrigues, J.J.; Lorenz, P. On the design of conditional privacy preserving batch verification-based authentication scheme for internet of vehicles deployment. IEEE Trans. Veh. Technol. 2020, 69, 5535–5548. [Google Scholar] [CrossRef]
- Tan, H.; Wang, M.; Shen, J.; Vijayakumar, P.; Moh, S.; Wu, Q.J. Blockchain-assisted conditional anonymous authentication and adaptive tree-based group key agreement for VANETs. IEEE Trans. Dependable Secur. Comput. 2025; Early Access. [Google Scholar] [CrossRef]
- Karati, A.; Islam, S.H.; Karuppiah, M. Provably secure and lightweight certificateless signature scheme for IIoT environments. IEEE Trans. Ind. Inform. 2018, 14, 3701–3711. [Google Scholar] [CrossRef]
- Zhang, B.; Zhu, T.; Hu, C.; Zhao, C. Cryptanalysis of a lightweight certificateless signature scheme for IIOT environments. IEEE Access 2018, 6, 73885–73894. [Google Scholar] [CrossRef]
- Chen, Y.; Yin, F.; Hu, S.; Sun, L.; Li, Y.; Xing, B.; Chen, L.; Guo, B. ECC-based authenticated key agreement protocol for industrial control system. IEEE Internet Things J. 2022, 10, 4688–4697. [Google Scholar] [CrossRef]
- Zhang, Y.; Zhao, S.; Qin, Y.; Yang, B.; Feng, D. Trusttokenf: A generic security framework for mobile two-factor authentication using trustzone. In Proceedings of the 2015 IEEE Trustcom/BigDataSE/ISPA; IEEE: New York, NY, USA, 2015; Volume 1, pp. 41–48. [Google Scholar]
- Balisane, R.A.; Martin, A. Trusted execution environment-based authentication gauge (TEEBAG). In Proceedings of the 2016 New Security Paradigms Workshop, Granby, CO, USA, 26–29 September 2016; pp. 61–67. [Google Scholar]
- Jiang, H.; Chang, R.; Ren, L.; Dong, W.; Jiang, L.; Yang, S. An effective authentication for client application using ARM trustzone. In Proceedings of the International Conference on Information Security Practice and Experience; Springer: Berlin/Heidelberg, Germany, 2017; pp. 802–813. [Google Scholar]
- Asaar, M.R.; Al-Baghdadi, M.I.A. Security Enhancement of an Authentication Scheme Based on DAC and Intel SGX in WSNs. ISC Int. J. Inf. Secur. 2024, 16, 149–163. [Google Scholar]
- Mao, W.; Jiang, P.; Zhu, L. BTAA: Blockchain and TEE-assisted authentication for IoT systems. IEEE Internet Things J. 2023, 10, 12603–12615. [Google Scholar] [CrossRef]
- Hou, Q.; Hsu, C.; Au, M.H.; Hu, H.; Zhao, Z.; Wu, Z. Efficient and provably secure privacy-preserving two-factor authentication and key-agreement using blockchain and TEE for IoV environments. J. Syst. Archit. 2025, 164, 103422. [Google Scholar] [CrossRef]
- Xue, K.; Ma, C.; Hong, P.; Ding, R. A temporal-credential-based mutual authentication and key agreement scheme for wireless sensor networks. J. Netw. Comput. Appl. 2013, 36, 316–323. [Google Scholar] [CrossRef]
- Wang, G.; Liu, Q. Chaotic Map-Based Authentication and Key Agreement Protocol with Low-Latency for Metasystem. Comput. Mater. Contin. 2024, 78, 4471–4488. [Google Scholar] [CrossRef]
- Mukhtar, M.A.; Bhatti, M.K.; Gogniat, G. Architectures for Security: A comparative analysis of hardware security features in Intel SGX and ARM TrustZone. In Proceedings of the 2019 2nd International Conference on Communication, Computing and Digital Systems (C-CODE); IEEE: New York, NY, USA, 2019; pp. 299–304. [Google Scholar]
- Wang, W.; Xie, Q.; Han, Z.; Su, C.; Rodrigues, J.J.; Wu, K. Secure Enhanced IoT-WLAN Authentication Protocol with Efficient Fast Reconnection. IEEE Trans. Mob. Comput. 2025, 24, 10085–10098. [Google Scholar] [CrossRef]
- Xu, Z.; Liang, W.; Li, K.C.; Xu, J.; Zomaya, A.Y.; Zhang, J. A time-sensitive token-based anonymous authentication and dynamic group key agreement scheme for industry 5.0. IEEE Trans. Ind. Inform. 2021, 18, 7118–7127. [Google Scholar] [CrossRef]
- Lee, H.; Kang, D.; Ryu, J.; Won, D.; Kim, H.; Lee, Y. A three-factor anonymous user authentication scheme for Internet of Things environments. J. Inf. Secur. Appl. 2020, 52, 102494. [Google Scholar] [CrossRef]
- Ryu, J.; Kang, D.; Lee, H.; Kim, H.; Won, D. A secure and lightweight three-factor-based authentication scheme for smart healthcare systems. Sensors 2020, 20, 7136. [Google Scholar] [CrossRef]
- Wu, F.; Li, X.; Xu, L.; Vijayakumar, P.; Kumar, N. A novel three-factor authentication protocol for wireless sensor networks with IoT notion. IEEE Syst. J. 2020, 15, 1120–1129. [Google Scholar] [CrossRef]
- Chaudhry, S.A.; Irshad, A.; Yahya, K.; Kumar, N.; Alazab, M.; Zikria, Y.B. Rotating behind privacy: An improved lightweight authentication scheme for cloud-based IoT environment. ACM Trans. Internet Technol. (TOIT) 2021, 21, 1–19. [Google Scholar] [CrossRef]
- Li, Y.; Tian, Y. A lightweight and secure three-factor authentication protocol with adaptive privacy-preserving property for wireless sensor networks. IEEE Syst. J. 2022, 16, 6197–6208. [Google Scholar] [CrossRef]
- Wu, T.Y.; Wang, L.; Guo, X.; Chen, Y.C.; Chu, S.C. SAKAP: SGX-based authentication key agreement protocol in IoT-enabled cloud computing. Sustainability 2022, 14, 11054. [Google Scholar] [CrossRef]
- Wang, J.; Hao, S.; Li, Y.; Fan, C.; Wang, J.; Han, L.; Hong, Z.; Hu, H. Challenges towards protecting vnf with sgx. In Proceedings of the 2018 ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization; ACM: New York, NY, USA, 2018; pp. 39–42. [Google Scholar]
- Fan, Q.; Chen, J.; Shojafar, M.; Kumari, S.; He, D. SAKE*: A symmetric authenticated key exchange protocol with perfect forward secrecy for industrial Internet of Things. IEEE Trans. Ind. Inform. 2022, 18, 6424–6434. [Google Scholar] [CrossRef]
- Satpathy, S.P.; Mohanty, S.; Pradhan, M. A sustainable mutual authentication protocol for IoT-Fog-Cloud environment. Peer-to-Peer Netw. Appl. 2025, 18, 35. [Google Scholar] [CrossRef]








| Notation | Definition |
|---|---|
| system administrator. | |
| i- legitimate user. | |
| smartcard. | |
| j- legitimate sensing device. | |
| identity of , , and . | |
| biometrics of . | |
| password of . | |
| biometric-derived secret parameter. | |
| master key for registration. | |
| X | master key of . |
| session key. | |
| current system timestamps. | |
| random numbers. | |
| system administrator. | |
| the adversary. | |
| one-way hash function. | |
| biometric fuzzy extraction function. | |
| ‖ | the bitwise concatenation operation. |
| ⊕ | the XOR operation. |
| Property | [46] | [47] | [48] | [49] | [50] | [51] | Ours |
|---|---|---|---|---|---|---|---|
| Online registration | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | ✔ |
| Dynamic credential | ✕ | ✕ | ✕ | ✔ | ✔ | ✕ | ✔ |
| Mutual authentication | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ |
| Forward security | ✔ | ✕ | ✔ | ✔ | ✔ | ✔ | ✔ |
| Privileged user attack | ✔ | ✕ | ✔ | ✕ | ✕ | ✔ | ✔ |
| Offline guessing attack | ✕ | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ |
| Online guessing attack | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ |
| Tracking attack | ✕ | ✕ | ✕ | ✔ | ✔ | ✕ | ✔ |
| Replay attack | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ |
| Man-in-the-middle attack | ✕ | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ |
| Sensing devices capture attack | ✕ | ✕ | ✕ | ✔ | ✕ | ✕ | ✔ |
| Mitigating side-channel attack | ✕ | ✕ | ✕ | ✕ | ✕ | ✔ | ✔ |
| Notation | Operation | Raspberry Pi | Computer |
|---|---|---|---|
| Hash function | 0.02 ms | 0.003 ms | |
| Fuzzy extractor | 2.226 ms | − | |
| AES encryption/decryption | 0.142 ms | 0.05 ms |
| Schemes | Total/ms | |||
|---|---|---|---|---|
| Lee et al. [46] | 2.647 | |||
| Ryu et al. [47] | 2.768 | |||
| Wu et al. [48] | 2.543 | |||
| Chaudhry et al. [49] | 2.868 | |||
| Li et al. [50] | 2.605 | |||
| Wu et al. [51] | 2.684 | |||
| Ours | 2.585 |
| Schemes | /Bits | /Bits | /Bits | Total/Bits | |||
|---|---|---|---|---|---|---|---|
| XMT | RX | XMT | RX | XMT | RX | ||
| Lee et al. [46] | 672 | 672 | 1824 | 1472 | 800 | 1152 | 3296 |
| Ryu et al. [47] | 672 | 544 | 1568 | 1184 | 512 | 1024 | 2752 |
| Wu et al. [48] | 992 | 672 | 1184 | 1344 | 352 | 512 | 2528 |
| Chaudhry et al. [49] | 672 | 864 | 1376 | 1184 | 512 | 512 | 2560 |
| Li et al. [50] | 832 | 512 | 1184 | 1184 | 352 | 672 | 2368 |
| Wu et al. [51] | 672 | 352 | 1504 | 1344 | 672 | 1152 | 2848 |
| Ours | 672 | 352 | 1024 | 1024 | 352 | 672 | 2048 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Guo, Z.; Liu, Y.; He, W.; Hu, X.; Zhang, H.; Tu, T. SGX-Based Efficient Three-Factor Authentication Scheme with Online Registration for Industrial Internet of Things. Electronics 2026, 15, 1180. https://doi.org/10.3390/electronics15061180
Guo Z, Liu Y, He W, Hu X, Zhang H, Tu T. SGX-Based Efficient Three-Factor Authentication Scheme with Online Registration for Industrial Internet of Things. Electronics. 2026; 15(6):1180. https://doi.org/10.3390/electronics15061180
Chicago/Turabian StyleGuo, Zhenbin, Yang Liu, Wenchen He, Xiaoxu Hu, Hua Zhang, and Tengfei Tu. 2026. "SGX-Based Efficient Three-Factor Authentication Scheme with Online Registration for Industrial Internet of Things" Electronics 15, no. 6: 1180. https://doi.org/10.3390/electronics15061180
APA StyleGuo, Z., Liu, Y., He, W., Hu, X., Zhang, H., & Tu, T. (2026). SGX-Based Efficient Three-Factor Authentication Scheme with Online Registration for Industrial Internet of Things. Electronics, 15(6), 1180. https://doi.org/10.3390/electronics15061180

