S2-Code: A Resilient and Lightweight Self-Synchronizing Authentication Protocol for Unreliable IoT Networks


Cao Y. Kou M. Lai Y. Mei Z.
2025Institute of Electrical and Electronics Engineers Inc.

IEEE Access
2025#13156153 - 156169 pp.

Reliable authentication in resource-constrained IoT remains challenging on lossy wireless links, which induce desynchronization and amplify denial-of-service (DoS) risk. We present S2-Code, a self-synchronizing symmetric protocol that couples a dual-window state machine with an AEAD-protected bidirectional token. We derive practical window-sizing bounds from packet loss/reordering, request rate, and offline duration, and validate the design via symbolic verification in ProVerif, network emulation in Mininet, and hardware experiments on Raspberry Pi and ESP32-C3. S2-Code achieves 100% session recovery after a catastrophic 50-count desynchronization where rolling codes fail. Under 30% packet loss, it sustains 60% success versus 20% for the rolling-code baseline (p < 10-8). A layered DoS defense—kernel-level rate limiting (nftables) plus an adaptive protocol mechanism—raises legitimate success from ≈ 17 % under flooding to ≈ 92.9 % under protocol-aware attack. The protocol has a small footprint (<8 KB flash, <4 KB RAM), low overhead (≈ 114 -byte packets, <17 ms latency), and scales to 100 concurrent devices in emulation. S2-Code offers a practical, robust middle ground between fragile rolling codes and heavyweight PKI for resource-constrained IoT.

denial-of-service (DoS) , IoT authentication , lightweight protocol , out-of-step recovery , robustness , rolling code , self-synchronization

Text of the article Перейти на текст статьи

Institute of Automation and Information Technology, Satbayev University, Almaty, 050013, Kazakhstan
Al-Farabi Kazakh National University, Higher School of Economics and Business, Almaty, 050040, Kazakhstan
Kyrgyzstan National University, Bishkek, 720033, Kyrgyzstan
Chongqing Vocational and Technical University of Mechatronics, Chongqing, 401120, China
School of Computer Science, Xi’an Shiyou University, Xi’an, 710065, China

Institute of Automation and Information Technology
Al-Farabi Kazakh National University
Kyrgyzstan National University
Chongqing Vocational and Technical University of Mechatronics
School of Computer Science

10 лет помогаем публиковать статьи Международный издатель

Книга Публикация научной статьи Волощук 2026 Book Publication of a scientific article 2026