Submitted:
25 June 2023
Posted:
26 June 2023
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Design Constraints and Security Issues in WSNs
2.1. Physical Characteristics and Constraints
- Limited battery capacity—Sensor networks are usually deployed in outdoor environment. Due to the size limitation, each sensor is usually equipped with a small battery. As a result, a sensor is unable to calculate and communicate when the battery runs out.
- Limited memory—The cache size of a sensor is usually tens of megabytes, which puts forward higher requirements for the length and number of keys stored.
- Limited bandwidth—Due to power limitation, most sensors use narrowband signal transmission, and the transmission rate generally does not exceed 10KB/s.
- Limited calculation power—In order to reduce the power consumption of CPU, most sensor nodes only use 8-bit 4-MHz microcontrollers.
- Good scalability—Wireless sensor network must allow new legal nodes to join the existing network at any time. At the same time, the failure of any node will not affect the normal operation of the network.
- Variability of network topology—Since sensors are often installed on mobile devices, the topology of wireless sensor networks often changes as well. Thus, network stability and nodes connectivity should be ensured in all protocols design.
- Environment—Some wireless sensor networks are expected to be used for remote control and reconnaissance, and are deployed in insecure and unstable environments, which makes them subject to many attacks, such as spoofing attacks, physical damage and any other mechanical failure associated with environmental factors.
2.2. Security Issues in WSNs
2.3. Aasymmetric Cryptography in WSNs
3. The Key Management Scheme for Cluster based WSNs
3.1. Network Model and Assumptions
- The base station has more energy power for calculations and communications compared to sensors.
- The base station owns a pair of keys (a public key and a private key).
- The network is divided into several cluster region. In each cluster, there is only one cluster head node, and its location remains unchanged. Each cluster head can be recognized as the gateway of its cluster.
- In terms of security and ease of management, each cluster generates different session key for dialogs between sensor nodes and cluster head.
- Both asymmetric and symmetric cryptography are used for each sensor. The former provides mutual authentication and key distribution, the latter ensures the confidentiality of traffic transmitted.
- As an optional technology in our scheme, MAC (message authentication code) provides data integrity.
- Public key is preloaded into each sensor and cluster head by an off-line dealer.
- Each sensor can store at least one public key and several session keys in its memory.
- Each sensor can randomly move among different clusters with a low speed.
3.2. Network Initializtion and Definitions

3.3. Static Sensors Subscheme for Hierarchical WSNs
3.3.1. Mutual Authentication and Key Distribution Process
-
Generation of the SKi: The CHi generates a random symmetric key SKi and a challenge R. Then, the CHi encrypts SKi , R and ID_CHi with PUK, and we get:Cipher1= E(PUK, SKi ‖ R‖ ID_CHi‖ timestamp)The 2-byte timestamp is used to resist replay attacks. CHi sends Cipher1 to the base station using traditional routing. Here, the PUK is used for authentication and confidentiality of the session key SKi.
- Establishment of SKi: After receiving and decrypting the message, the base station gets SKi, R using its PVK and builds a global table of all the session keys of different clusters. This table is used to identify the cluster and its cluster head on the network. Meanwhile, if ID_Chi can be found in the database of legal CHs, the identity of the CHi can be authenticated by BS.
- Completion of the handshake: The base station encrypts R with the established session key SKi. and getsCipher2= E(SKi, R)

3.3.2. Session Key Update Process
- The new session key SKi’ is generated by the cluster head CHi at a certain moment.
- CHi notifies the base station to update the session key.
- Using the proposed handshake operation, the new session key SKi’ is distributed between the BS and the CHi. After that, the CHi notifies all the sensors to update their session key in its cluster with a broadcasting message. Sensors will stop encrypting sessions until they receive new session key SKi’.
- After the establishment of SKi’, the CHi distributes SKi’ encrypted with the original session key SKi to all the sensors by broadcasting cipher5, denoted asCipher5= E(SKi, SKi’).
- Each sensor in the cluster decrypts the cipher5 with the old session key SKi and substitutes with the SKi’. The subsequent dialog is decrypted by the new session key.
3.4. Mobile Sensors Subscheme for Hierarchical WSNs
3.4.1. Mutual Authentication and Key Distribution Process
- When S0 moves into cluster2, it will send a cluster-entry request to CH2. The cluster forming and cluster head detection process is not described here, please refer to [24].
- CH2 detects and receives this message. Then, CH2 replies to S0 with a message including its identification code ID_CH2.
- S0 updates the identification of the present cluster, replacing ID_CH0 with ID_CH2.
- S0 applies for the latest session key SK2 from the base station with the cipher6 denoted as follows:Cipher6= E(PUK, ID_CH2 ‖ ID_S0 ‖ timestamp ‖ SK_ S0 ‖ R)
-
The BS decrypts cipher6 with the PVK and gets ID_CH2, SK_ S0, and ID_S0 fromPlain6 = D(PVK, Cipher6)= D(PVK, E(PUK, ID_CH2 ‖ ID_S0 ‖ timestamp ‖ SK_ S0 ‖ R)) = ID_CH2 ‖ ID_S0‖ SK_ S0 ‖ R.The latest session key SK2 can be picked out in terms of ID_CH2, and the S0 is authenticated by BS according to ID_S0. Then, the cipher7 will be sent to S0. The cipher7 is built as follows:Cipher7= E(SK_ S0, SK2 ‖ R).
- S0 decrypts the cipher7 with the symmetric key SK_ S0 and successfully gets SK2.


3.4.2. Session Key Update Process
4. Analysis and Comparison
4.1. Key Storage of Sensor Nodes
4.2. Communication Overhead
4.3. Security Analysis
4.3.1. Mutual Authentication
4.3.2. Security Connectivity

4.3.3. Resistance to Attacks

| Scheme features | Du [15] | Lee [17] | Benamar [20] | Erfani [23] | Our Scheme |
|---|---|---|---|---|---|
| Public key encryption | — | √ | √ | — | √ |
| Key predistribution | √ | ⅹ | √ | √ | √ |
| Mobility of sensors | — | ⅹ | ⅹ | √ | √ |
| Perfect resilience against node capture | ⅹ | — | — | ⅹ | √ |
| Mutual authentication | ⅹ | √ | ⅹ | ⅹ | √ |
| Resistant to eavesdropping attacks | — | — | √ | √ | √ |
5. Conclusions
Author Contributions
Data Availability Statement
Conflicts of Interest
References
- Dludla, A.G.; Abu-Mahfouz, A.M.; Kruger, C.P.; Isaac, J.S. Wireless sensor networks testbed: ASNTbed. In Proceedings of the 2013 IEEE IST-Africa Conference and Exhibition (IST-Africa), Nairobi, Kenya, 29–31 May 2013; pp. 1–10. [Google Scholar]
- Abu-Mahfouz, A.M.; Steyn, L.P.; Isaac, S.J.; Hancke, G.P. MultiLevel Infrastructure of Interconnected Testbeds of Large-Scale Wireless Sensor Networks (MI2T-WSN). In Proceedings of the International Conference on Wireless Networks (ICWN), Athens, Greece, 1–7 January 2012; p. 1. [Google Scholar]
- Carman, D.W.; Kruus, P.S.; Matt, B. Constraints and approaches for distributed sensor network security (final); NAI Labs Technical Report; NAI Labs: MD, USA, 2000; pp. 1–139. [Google Scholar]
- Ren, Y.; Leng, Y.; Qi, J.; Sharma, P.K.; Wang, J.; Almakhadmeh, Z.; Tolba, A. Multiple cloud storage mechanism based on blockchain in smart homes. Future Generation Computer Systems 2021, 115, 304–313. [Google Scholar] [CrossRef]
- Xiong, J.; Zhao, M.; Bhuiyan, M.Z.A.; Chen, L.; Tian, Y. An AI-enabled three-party game framework for guaranteed data privacy in mobile edge crowdsensing of IoT. IEEE Transactions on Industrial Informatics 2021, 17, 922–933. [Google Scholar] [CrossRef]
- Aysal, T.C.; Barner, K.E. Sensor data cryptography in wireless sensor networks. IEEE Transactions on Information Forensics and Security 2008, 3, 273–289. [Google Scholar] [CrossRef]
- Giruka, V.C.; Singhal, M.; Royalty, J.; Varanasi, S. Security in wireless sensor networks. Wireless Communications and Mobile Computing 2008, 8, 1–24. [Google Scholar] [CrossRef]
- Kundur, D.; Luh, W.; Okorafor, U.N.; Zourntos, T. Security and privacy for distributed multimedia sensor networks. Proceedings of the IEEE 2008, 96, 112–130. [Google Scholar] [CrossRef]
- Wang, Y.; Attebury, G.; Ramamurthy, B. A survey of security issues in wireless sensor networks. IEEE Communications Surveys & Tutorials 2006, 8, 2–23. [Google Scholar]
- Liu, G.; Yang, Q.; Wang, H. Trust assessment in online social networks. IEEE Transactions on Dependable and Secure Computing 2018, 2, 994–1007. [Google Scholar] [CrossRef]
- Ge, C.; Susilo, W.; Baek, J.; Liu, Z.; Xia, J.; Fang, L. Revocable attribute-based encryption with data integrity in clouds. IEEE Transactions on Dependable and Secure Computing 2021, 21, 1. [Google Scholar] [CrossRef]
- Ge, C.; Susilo, W.; Liu, Z.; Xia, J.; Szalachowski, P.; Liming, F. Secure keyword search and data sharing mechanism for cloud computing. IEEE Transactions on Dependable and Secure Computing 2020, 20, 1. [Google Scholar] [CrossRef]
- Zheng, J.; Jamalipour, A. Wireless Sensor Networks: A Networking Perspective; a book published by A John & Sons, Inc, and IEEEE; 2009. [Google Scholar]
- Singh, S.K.; Singh, M.P.; Singh, D.K. Routing Protocols in Wireless Sensor Networks – A Survey. International Journal of Computer Science & Engineering Survey 2010, 1. [Google Scholar]
- Du, X.; Xiao, Y.; Guizani, M.; Chen, H.-H. An effective key management scheme for heterogeneous sensor networks. Ad Hoc Networks 2007, 5, 24–34. [Google Scholar] [CrossRef]
- Boujelben, M.; Cheikhrouhou, O.; Abid, M.; Youssef, H. Establishing pairwise keys in heterogeneous two-tiered wireless sensor networks. In Proceedings of the 3rd International Conference on Sensor Technologies and Applications Athens, Athens, Greece; 2009; pp. 18–23. [Google Scholar]
- Lee, S.; Kim, K. Key renewal scheme with sensor authentication under clustered wireless sensor networks. Electronics Letters 2015, 51, 368–369. [Google Scholar] [CrossRef]
- Tian, Y.; Wang, Z.; Xiong, J.; Ma, J. A blockchain-based secure key management scheme with trustworthiness in DWSNs. IEEE Transactions on Industrial Informatics 2020, 16, 6193–6202. [Google Scholar] [CrossRef]
- Gura, N.; Patel, A.; Wander, A.; Eberle, H.; Shantz, S.C. Comparing elliptic curve cryptography and RSA on 8-bit CPUs. In Proceedings of the Sixth Workshop on Cryptographic Hardware and Embedded Systems; 2004; pp. 119–132. [Google Scholar]
- Benamar, K.; Mohammed, F.; Abdellah, M. Architecture aware key management scheme for wireless sensor networks. International Journal of Information Technology & Computer Science 2012, 4, 50–59. [Google Scholar]
- Crossbow Technology Inc., Processor/Radio Modules, 2008. (http://www.xbow.com).
- Chatterjee, U.; Chakraborty, R.S.; Mukhopadhyay, D. A PUF-based secure communication protocol for IoT. ACM Transactions on Embedded Computing Systems 2017, 16, 1–25. [Google Scholar] [CrossRef]
- Erfani, S.H.; Javadi, H.H.S.; Rahmani, A.M. A dynamic key management scheme for dynamic wireless sensor networks. Security and Communication Networks 2015, 8, 1040–1049. [Google Scholar] [CrossRef]
- Mohamed, Y.; Moustafa, Y.; Khaled, A. Energy-aware management for cluster-based sensor networks. Computer Networks 2003, 43, 649–668. [Google Scholar]
- Eschenauer, L.; Gligor, V.D. A key management scheme for distributed sensor networks. In Proceedings of the ACM Conference on Computer and Communication Security, Washington, DC, USA, November 2002; pp. 41–47. [Google Scholar]
- Chen, C.Y.; Chao, H.C. A survey of key distribution in wireless sensor networks. Security and Communication Networks 2014, 7. [Google Scholar] [CrossRef]
- University of Southern California: “The network simulator – ns-2”. Available at http://www.isi.edu/nsnam/ns/, September 2005.
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2023 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).