Journal article
Cryptanalysis and Improvement of the SMEP-IoV Protocol: A Secure and Lightweight Protocol for Message Exchange in IoV Paradigm
IoT, Vol.7(2), pp.1-30
31/03/2026
Metrics
1 Record Views
Abstract
The Internet of Vehicles (IoV) is a rapidly evolving technology that provides real-time connectivity, enhanced road safety, and reduced traffic congestion; however, its inherently open communication channels expose it to serious security and privacy threats. In 2021, Chaudhry proposed SMEP-IoV, a lightweight message authentication protocol designed to satisfy essential security requirements. This paper presents a comprehensive security analysis of SMEP-IoV and reveals several serious vulnerabilities. Specifically, sensitive credentials are stored in plaintext without tamper-resistant protection, and both authentication and session key derivation depend directly on these credentials. These structural flaws allow an adversary to extract the stored secrets, generate valid authentication messages, and derive the established session key, enabling vehicle impersonation and session key disclosure attacks. Moreover, compromise of long-term secrets facilitates key compromise impersonation attacks. It also fails to ensure anonymity and perfect forward secrecy. To address these issues, we propose an enhanced authentication protocol for resource-constrained IoV environments, leveraging a three-factor authentication mechanism combined with lightweight cryptographic primitives. Formal security analyses using BAN logic, Tamarin, and ProVerif confirm its resilience against known attacks, while NS-3 simulations validate its scalability, high throughput, and low End-to-End Delay (E2ED). The results highlight the protocol as a robust, efficient, and scalable solution for large-scale IoV deployments.
Details
- Title
- Cryptanalysis and Improvement of the SMEP-IoV Protocol: A Secure and Lightweight Protocol for Message Exchange in IoV Paradigm
- Creators
- Gelare Oudi Ghadim - Isfahan University of TechnologyParvin Rastegari - Isfahan University of TechnologyMohammad Dakhilalian - Isfahan University of TechnologyFaramarz Hendessi - Isfahan University of TechnologyShahrzad Saremi - University of the Sunshine CoastRania Shibl - University of the Sunshine CoastYassine Himeur - University of DubaiShadi Atalla - University of DubaiWathiq Mansoor - University of Baghdad
- Publication Details
- IoT, Vol.7(2), pp.1-30
- Publisher
- MDPI AG
- Identifiers
- 991013370446202368
- Copyright
- © 2026 by the authors.
- Academic Unit
- Faculty of Science and Engineering
- Language
- English
- Resource Type
- Journal article