Abstract
Reliable authentication in resource-constrained IoT remains challenging on lossy wireless links, which induce desynchronization and amplify denial-of-service (DoS) risk. We present S2-Code, a self-synchronizing symmetric protocol that couples a dual-window state machine with an AEAD-protected bidirectional token. We derive practical window-sizing bounds from packet loss/reordering, request rate, and offline duration, and validate the design via symbolic verification in ProVerif, network emulation in Mininet, and hardware experiments on Raspberry Pi and ESP32-C3. S2-Code achieves 100% session recovery after a catastrophic 50-count desynchronization where rolling codes fail. Under 30% packet loss, it sustains 60% success versus 20% for the rolling-code baseline (p < 10-8). A layered DoS defense—kernel-level rate limiting (nftables) plus an adaptive protocol mechanism—raises legitimate success from ≈ 17 % under flooding to ≈ 92.9 % under protocol-aware attack. The protocol has a small footprint (<8 KB flash, <4 KB RAM), low overhead (≈ 114 -byte packets, <17 ms latency), and scales to 100 concurrent devices in emulation. S2-Code offers a practical, robust middle ground between fragile rolling codes and heavyweight PKI for resource-constrained IoT.
Author supplied keywords
Cite
CITATION STYLE
Cao, Y., Kou, M., Lai, Y., & Mei, Z. (2025). S2-Code: A Resilient and Lightweight Self-Synchronizing Authentication Protocol for Unreliable IoT Networks. IEEE Access, 13, 156153–156169. https://doi.org/10.1109/ACCESS.2025.3605060
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.