| Title: | Cryptanalysis of an authentication protocol for edge-centric maritime transportation systems |
|---|
| Authors: | ID Liu, Shuangshuang (Author) ID Hölbl, Marko (Author) ID Renato R. Maaliw (Author) ID Mia, Solaiman (Author) |
| Files: | JRSC-tsH7sbJEW06YMvzEP.pdf (1,72 MB) MD5: 74415E2A0291EA99C566C997D1AD7921
|
|---|
| Language: | English |
|---|
| Work type: | Article |
|---|
| Typology: | 1.01 - Original Scientific Article |
|---|
| Organization: | FERI - Faculty of Electrical Engineering and Computer Science
|
|---|
| Abstract: | With the rapid development of edge computing and intelligent maritime transportation systems, secure authentication and key agreement protocols have become essential for protecting communications among maritime entities and edge devices. Recently, Mahmood et al. proposed an authentication protocol for edge-centric maritime transportation systems, claiming that their scheme can resist various security attacks while ensuring efficient communication. However, practical maritime environments still face many security threats. In addition, edge infrastructures usually have limited resources. Therefore, authentication protocols require rigorous security evaluation. In this paper, we perform a cryptanalysis of Mahmood et al.'s protocol and reveal several critical security weaknesses. We demonstrate that the protocol is vulnerable to temporary random-number leakage attacks and privileged insider attacks, which may enable adversaries to compromise authentication information and session security. Moreover, we show that the protocol fails to provide perfect forward secrecy, meaning that previously established session keys may be exposed once long-term secret credentials are compromised. These vulnerabilities reduce the security reliability and practical applicability of the original scheme in real-world maritime transportation environments. To address these issues, we discuss several measures for improvement and provide recommendations to strengthen the protocol's security. Our analysis provides useful guidance for the future design of secure authentication protocols in edge-centric maritime transportation systems. |
|---|
| Keywords: | edge computing, intelligent maritime transportation systems, authentication protocol, temporary random number leakage attack, privileged insider attack, perfect forward secrecy |
|---|
| Publication status: | Published |
|---|
| Publication version: | Version of Record |
|---|
| Submitted for review: | 19.05.2026 |
|---|
| Article acceptance date: | 09.06.2026 |
|---|
| Publication date: | 14.06.2026 |
|---|
| Publisher: | ICCK |
|---|
| Year of publishing: | 2026 |
|---|
| Number of pages: | str. 104-110 |
|---|
| Numbering: | Vol. 2, no. 2 |
|---|
| PID: | 20.500.12556/DKUM-100104  |
|---|
| UDC: | 004.7 |
|---|
| ISSN on article: | 3070-6424 |
|---|
| COBISS.SI-ID: | 289536771  |
|---|
| DOI: | 10.62762/JRSC.2026.765456  |
|---|
| Copyright: | © 2026 by the Author(s) |
|---|
| Publication date in DKUM: | 04.09.2026 |
|---|
| Views: | 153 |
|---|
| Downloads: | 2 |
|---|
| Metadata: |  |
|---|
| Categories: | Misc.
|
|---|
|
:
|
Copy citation |
|---|
| | | | Average score: | (0 votes) |
|---|
| Your score: | Voting is allowed only for logged in users. |
|---|
| Share: |  |
|---|
Hover the mouse pointer over a document title to show the abstract or click
on the title to get all document metadata. |