Related Experiment Videos
Authentication Mechanisms in the Internet of Things: A Comparative Analysis Across RFID, Smart Grids, Vehicular
Supraja Ayyamgari1, Bala Yashwanth Reddy Thumma2, Nivedan Suresh3
1Department of Information Technology, University of the Cumberlands, Williamsburg, KY 40769, USA.
Abstract:
The Internet of Things (IoT) is envisioned to link billions of diverse devices together. To safeguard privacy of user data, ensure authenticity of the data communicated between these devices, and guarantee their availability, robust authentication is needed. On the other hand, authentication techniques face several security challenges because IoT devices are resource-constrained (memory, battery, processor, etc.). To elaborate on this, we perform an extensive survey of authentication mechanisms in IoT, addressing the resource-constrained nature of devices, heterogeneity of networks, and prospective security challenges. We focus on five major classes of authentication protocols-namely, password-based, MAC-based, public identity-based, token-based, and biometrics-based protocols-and compare them based on communication and computation overhead, energy efficiency, scalability, and security. We also highlight the applicability of authentication mechanisms to four popular IoT platforms: RFID systems, smart grids, the Internet of Vehicles (IoV), and smart homes. Finally, we survey trending solutions such as implicit authentication using biometrics, blockchain-based identity management, and trusted computing. Beyond the qualitative comparison, this updated survey presents a formal, PRISMA-style review process including inclusion and exclusion criteria; a quantitative/information theoretic comparison of authentication classes (using Shannon entropy and confusion- matrix-derived metrics, the false acceptance rate, false rejection rate, equal error rate, and receiver operating characteristic reasoning); and discussion of higher-layer auth architectures including federated identity management, single sign-on (SSO), and OAuth/OpenID Connect that enable device-level protocols. Existing systematic reviews and auth schemes published since 2023 are also included to supplement previously compared device-centric works. Our analysis shows that token-based authentication currently offers the most balanced trade-off among security, scalability, and energy overhead for general-purpose IoT deployments, while biometric and implicit biometric schemes provide the strongest resistance to impersonation at higher computational cost and public-identity (asymmetric) schemes scale well but remain impractical for the most resource-constrained endpoints. In summary and to guide future work directly, the survey also outlines four promising directions towards which the community should further research: (i) hybrid schemes based on lightweight cryptography and behavioral or physiological biometrics; (ii) lightweight post-quantum authentication schemes, resistant to quantum computer attacks and deployable on constrained devices; (iii) continuous authentication and anomaly detection based on machine learning techniques; and (iv) federated and decentralized (blockchain-enabled) identity management solutions towards the minimization of single points of failure among heterogeneous IoT areas.