TY - JOUR
T1 - Modified AKMA for Decentralized Authentication in LEO Satellite-Based IoT Networks
AU - Khan, Saud
AU - Durrani, Salman
AU - Thapa, Chandra
AU - Camtepe, Seyit
N1 - Publisher Copyright:
© 2014 IEEE.
PY - 2025
Y1 - 2025
N2 - Device authentication in Low Earth Orbit (LEO) satellite-based Internet of Things (IoT) networks is critical for enabling secure and reliable communication between remote IoT devices and satellites. It prevents unauthorized access and security breaches. State-of-the-art authentication methods for terrestrial networks, such as Authentication and Key Management for Applications (AKMA), are inadequate when directly applied to such networks because IoT devices have constrained communication and computational capabilities. Further, the satellite environment is highly dynamic, with frequent handovers and variable latency, leading to vulnerabilities like man-in-the-middle (MITM) and spoofing attacks. To address these challenges, we propose a modified AKMA framework for decentralized and continuous authentication in LEO satellite-based IoT networks. Our proposed modification utilizes local key refreshment for seed generation, seed update, and seed refreshment in a decentralized manner, enabling tailored transmission patterns for IoT devices. This reduces the need for repeated authentication attempts with satellites and effectively mitigates handoff-associated threats. We examine the authentication performance of the system in the presence of an illegitimate Unmanned Aerial Vehicle (UAV) above the legitimate IoT devices. Our results through simulations and emulation show improvement in the authentication rate of legitimate IoT devices and a reduction in the misdetection rate of illegitimate UAVs compared to state-of-the-art physical channel-based authentication schemes. Our proposed modified AKMA enables its application in LEO satellite-based IoT networks.
AB - Device authentication in Low Earth Orbit (LEO) satellite-based Internet of Things (IoT) networks is critical for enabling secure and reliable communication between remote IoT devices and satellites. It prevents unauthorized access and security breaches. State-of-the-art authentication methods for terrestrial networks, such as Authentication and Key Management for Applications (AKMA), are inadequate when directly applied to such networks because IoT devices have constrained communication and computational capabilities. Further, the satellite environment is highly dynamic, with frequent handovers and variable latency, leading to vulnerabilities like man-in-the-middle (MITM) and spoofing attacks. To address these challenges, we propose a modified AKMA framework for decentralized and continuous authentication in LEO satellite-based IoT networks. Our proposed modification utilizes local key refreshment for seed generation, seed update, and seed refreshment in a decentralized manner, enabling tailored transmission patterns for IoT devices. This reduces the need for repeated authentication attempts with satellites and effectively mitigates handoff-associated threats. We examine the authentication performance of the system in the presence of an illegitimate Unmanned Aerial Vehicle (UAV) above the legitimate IoT devices. Our results through simulations and emulation show improvement in the authentication rate of legitimate IoT devices and a reduction in the misdetection rate of illegitimate UAVs compared to state-of-the-art physical channel-based authentication schemes. Our proposed modified AKMA enables its application in LEO satellite-based IoT networks.
KW - lightweight authentication
KW - satellite communications
KW - Security of internet of things
UR - http://www.scopus.com/inward/record.url?scp=85214480658&partnerID=8YFLogxK
U2 - 10.1109/JIOT.2025.3526635
DO - 10.1109/JIOT.2025.3526635
M3 - Article
AN - SCOPUS:85214480658
SN - 2327-4662
JO - IEEE Internet of Things Journal
JF - IEEE Internet of Things Journal
ER -