Submitted:
30 May 2026
Posted:
01 June 2026
You are already at the latest version
Abstract
Keywords:
1. Introduction
1.1. Motivation
1.2. Major Contributions
1.3. Paper Organization
2. Related Work
3. Preliminaries
3.1. System Model
3.2. Security Model
3.3. Notations
| Notation | Descriptions |
|---|---|
| Fog node and edge node | |
| Set of private keys for cloud server, fog node and edge node | |
| Private keys for cloud server, fog node and edge node | |
| Set of secret parameters for cloud server, fog node and edge node | |
| Secret parameters for cloud server, fog node and edge node | |
| The real identity for fog node and edge node | |
| One way hash function | |
| The group key encryption key | |
| Temporary identity for fog node and edge node | |
| Timestamps | |
| Adversary | |
| and | Additive and multiplicative cyclic groups |
| A generator of cyclic group | |
| Euler function | |
| Product of all private keys | |
| No. of fog nodes | |
| No. of edge nodes | |
| Modular inverse of secret parameter of edge node | |
| Group Keys | |
| A secret random number of edge node |
4. Proposed Protocol
4.1. System Initialization

4.2. Fog Node Registration Phase
4.3. Edge Node Registration Phase
4.4. Group Key Distribution and Extraction Phase
4.5. Batch Verification Based on Group Key Phase
4.6. Group Key Update Phase
4.6.1. Single or Multiple Edge Nodes Join
4.6.2. Single or Multiple Edge Nodes Leave
5. Security Analysis
5.1. Informal Security Analysis
5.1.1. Forward Secrecy
5.1.2. Backward Secrecy
5.1.3. Message Integrity
5.1.4. Protection Against Modification Attack
5.1.5. Protection against Replay Attack
5.1.6. Protection Against Impersonation Attack
5.1.7. Data Confidentiality
5.2. Formal Security Verification Using ProVerif Tool
5.3. Security Verification Using Random Oracle Model
6. Performance Analysis
6.1. Security Feature Comparison
6.2. Computation Cost
6.3. Communication Cost
6.4. Performance Validation Using Wokwi
| Phases | Average latency ( | Average Energy Consumption (J) |
|---|---|---|
| Group key distribution by fog node | 27375 | 0.004125 |
| Group key retrieval by edge node | 7384 | 0.001064 |
| Single message verification | 6384 | 0.001203 |
| Batch message verification | 12886 | 0.001882 |
7. Conclusion
Declarations
Author Contributions
Funding
Data Availability
Conflicts of Interest
Ethics Approval
Consent to publish
Clinical trial number
References
- Guo, C., & Chang, C. C. (2014). An authenticated group key distribution protocol based on the generalized Chinese remainder theorem. International Journal of Communication Systems, 27(1), 126-134. [CrossRef]
- Zhang, J., Cui, J., Zhong, H., Chen, Z., & Liu, L. (2019). PA-CRT: Chinese remainder theorem based conditional privacy-preserving authentication scheme in vehicular ad-hoc networks. IEEE Transactions on Dependable and Secure Computing, 18(2), 722-735. [CrossRef]
- Ni, J., Zhang, K., Lin, X., & Shen, X. (2017). Securing fog computing for internet of things applications: Challenges and solutions. IEEE Communications Surveys & Tutorials, 20(1), 601-628. [CrossRef]
- Kumar, V., Kumar, R., & Pandey, S. K. (2020). A secure and robust group key distribution and authentication protocol with efficient rekey mechanism for dynamic access control in secure group communications. International Journal of Communication Systems, 33(14), e4465. [CrossRef]
- Kumar, V., Ahmad, M., & Kumari, A. (2019). A secure elliptic curve cryptography based mutual authentication protocol for cloud-assisted TMIS. Telematics and Informatics, 38, 100-117. [CrossRef]
- Amanlou, S., Hasan, M. K., & Bakar, K. A. A. (2021). Lightweight and secure authentication scheme for IoT network based on publish–subscribe fog computing model. Computer Networks, 199, 108465. [CrossRef]
- Wu, S., Zhang, A., & Luo, H. (2023). EF-CRT: Group key update and batch verification based on Euler function and Chinese remainder theorem for edge-fog computing networks. IEEE Systems Journal, 17(4), 5987-5998. [CrossRef]
- Kumar, V., Kumar, R., & Pandey, S. K. (2020). A computationally efficient centralized group key distribution protocol for secure multicast communications based upon RSA public key cryptosystem. Journal of King Saud University-Computer and Information Sciences, 32(9), 1081-1094. [CrossRef]
- Vijayakumar, P., Azees, M., Kannan, A., & Deborah, L. J. (2015). Dual authentication and key management techniques for secure data transmission in vehicular ad hoc networks. IEEE Transactions on Intelligent Transportation Systems, 17(4), 1015-1028. [CrossRef]
- Wazid, M., Bagga, P., Das, A. K., Shetty, S., Rodrigues, J. J., & Park, Y. (2019). AKM-IoV: Authenticated key management protocol in fog computing-based Internet of vehicles deployment. IEEE Internet of Things Journal, 6(5), 8804-8817 . [CrossRef]
- Awais, S. M., Yucheng, W., Mahmood, K., Badar, H. M. S., Kharel, R., & Das, A. K. (2024). Provably secure fog-based authentication protocol for VANETs. Computer Networks, 246, 110391. [CrossRef]
- Ali, H., & Ahmed, I. (2024). LAAKA: Lightweight anonymous authentication and key agreement scheme for secure fog-driven IoT systems. Computers & Security, 140, 103770. [CrossRef]
- Gupta, K., Kumar, V., Prakash, R., Pal, O., & Sharma, S. (2025). SAKM: A Scalable and Adaptive Key Management for Securing Demand-Response Bidirectional Communications in AMI of Next-Generation Smart Grids. Security and Privacy, 8(5), e70076. [CrossRef]
- Gupta, K., Kumar, V., Prakash, R., & Pal, O. (2025). SLMAS: a secure and lightweight mutual authentication scheme for telecare medical information system based on ECC. The Journal of Supercomputing, 81(5), 639. [CrossRef]
- Bayat, M., Barmshoory, M., Rahimi, M., & Aref, M. R. (2015). A secure authentication scheme for VANETs with batch verification. Wireless networks, 21(5), 1733-1743. [CrossRef]
- Wang, S., & Yao, N. (2017). LIAP: A local identity-based anonymous message authentication protocol in VANETs. Computer Communications, 112, 154-164. [CrossRef]
- Mei, Q., Xiong, H., Chen, J., Yang, M., Kumari, S., & Khan, M. K. (2020). Efficient certificateless aggregate signature with conditional privacy preservation in IoV. IEEE Systems Journal, 15(1), 245-256. [CrossRef]
- Feng, X., Shi, Q., Xie, Q., & Wang, L. (2021). P2BA: A privacy-preserving protocol with batch authentication against semi-trusted RSUs in vehicular ad hoc networks. IEEE Transactions on Information Forensics and Security, 16, 3888-3899. [CrossRef]
- Qi, J., Gao, T., Deng, X., & Zhao, C. (2022). A pseudonym-based certificateless privacy-preserving authentication scheme for VANETs. Vehicular Communications, 38, 100535. [CrossRef]
- Chen, S., Liu, Y., Ning, J., & Zhu, X. (2023). BASRAC: An efficient batch authentication scheme with rule-based access control for VANETs. Vehicular Communications, 40, 100575. [CrossRef]
- Kumar, V., Kumar, R., & Pandey, S. K. (2017, October). An enhanced and secured RSA public key cryptosystem algorithm using Chinese remainder theorem. In International Conference on Next Generation Computing Technologies (pp. 543-554). Singapore: Springer Singapore.
- Cui, J., Tao, X., Zhang, J., Xu, Y., & Zhong, H. (2018). HCPA-GKA: A hash function-based conditional privacy-preserving authentication and group-key agreement scheme for VANETs. Vehicular communications, 14, 15-25. [CrossRef]
- Shao, J., Lin, X., Lu, R., & Zuo, C. (2015). A threshold anonymous authentication protocol for VANETs. IEEE Transactions on vehicular technology, 65(3), 1711-1720. [CrossRef]
- Zhong, H., Han, S., Cui, J., Zhang, J., & Xu, Y. (2019). Privacy-preserving authentication scheme with full aggregation in VANET. Information Sciences, 476, 211-221. [CrossRef]
- Ali, I., Lawrence, T., Omala, A. A., & Li, F. (2020). An efficient hybrid signcryption scheme with conditional privacy-preservation for heterogeneous vehicular communication in VANETs. IEEE Transactions on Vehicular Technology, 69(10), 11266-11280. [CrossRef]
- Blanchet, B., Smyth, B., Cheval, V., & Sylvestre, M. (2018). ProVerif 2.00: automatic cryptographic protocol verifier, user manual and tutorial. Version from, 16, 05-16.
- Vijayakumar, P., Bose, S., & Kannan, A. (2012). Chinese remainder theorem based centralised group key management for secure multicast communication. IET Inf. Secur. 8 (3), 179–187 (2014). [CrossRef]
- Z. Chen et al., “A group signature scheme based on Chinese residual theorem,” Acta Electronica Sinica, vol. 32, no. 7, pp. 1062–1065, 2004.
- X. Zheng et al., “Chinese remainder theorem-based group key management,” in Proc. 45th Annu. Southeast Regional Conf., 2007, pp. 266–271.
- S. Agrawal and M. Das, “Mutual healing enabled group-key distribution protocol in wireless sensor networks,” Comput. Commun., vol. 112, pp. 131–140, 2017. [CrossRef]
- Kumar, V., Kumar, R. & Pandey, S.K. LKM-AMI: A Lightweight Key Management Scheme for Secure Two-Way Communications between Smart Meters and HAN Devices of AMI System in Smart Grid. Peer-to-Peer Netw. Appl. 14, 82–100 (2021). [CrossRef]
- Gupta, K., Kumar, V. KMS–AMI: an efficient and scalable key management scheme for secure two-way communications in advanced metering infrastructure of smart grid. J Supercomput 80, 8668–8701 (2024). [CrossRef]
- Sahu, P., Kumar, V., Gupta, K. et al. PMA-KDP: privacy-preserving mutual authentication and key distribution protocol in Vehicular Ad-hoc Networks (VANETs). Multimed Tools Appl 83, 87505–87526 (2024). [CrossRef]











| Cryptographic operations | Time taken(ms) |
|---|---|
| : hash operation | 0.005 |
| : Bilinear pairing operation | 14.293 |
| : Scalar multiplication | 4.141 |
| : Exponentiation operation | 1.388 |
| : Point addition | 0.33 |
| : Map-to-point hash operation | 11.875 |
| : Multiplication | 0.015 |
| : Small scalar multiplication | 0.387 |
| Cryptographic symbols | Size (byte) |
|---|---|
| 128 | |
| 20 | |
| 128 | |
| 4 |
| Protocol(s) | Security Features | |||||||
| Bayat et al. [15] | √ | √ | √ | √ | ||||
| Wang et al. [16] | √ | √ | √ | √ | √ | |||
| Mei et al. [17] | √ | √ | √ | √ | √ | √ | ||
| Feng et al. [18] | √ | √ | √ | √ | √ | |||
| Qi et al. [19] | √ | √ | √ | √ | √ | √ | √ | |
| Chen et al. [20] | √ | √ | √ | √ | √ | √ | √ | |
| Our | √ | √ | √ | √ | √ | √ | √ | √ |
| Protocol(s) | Message sign | Single verification | Batch verification |
|---|---|---|---|
| Bayat et al. [15] | 5+++2 32.95 |
3+++ 58.9 |
3+n+n+ +n 41.889+17.011n |
| Wang et al. [16] | 5+2+ 44.785 |
3+++ 58.91 |
3+n+n+ + 41.889+17.021n |
| Mei et al. [17] |
+2 40.31 |
+2 65.454 |
+2n 57.172+8.282n |
| Feng et al. [18] |
+11+12 90.993 |
+10+10 112.462 |
+ 50.031+24.846n |
| Qi et al. [19] |
+4 30.857 |
2+4 45.15 |
+4n 14.293+30.857n |
| Chen et al. [20] |
+ 8.612 |
2+++ 34.445 |
+n+2n+ +n+n 27.926+7.308n |
| Our |
+ 4.471 |
2+++2 33.067 |
2++2n+2n 32.727+0.67n |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).