S2-Code: A Resilient and Lightweight Self-Synchronizing Authentication Protocol for Unreliable IoT Networks
Cao Y. Kou M. Lai Y. Mei Z.
2025Institute of Electrical and Electronics Engineers Inc.
IEEE Access
2025#13156153 - 156169 pp.
Reliable authentication in resource-constrained IoT remains challenging on lossy wireless links, which induce desynchronization and amplify denial-of-service (DoS) risk. We present S2-Code, a self-synchronizing symmetric protocol that couples a dual-window state machine with an AEAD-protected bidirectional token. We derive practical window-sizing bounds from packet loss/reordering, request rate, and offline duration, and validate the design via symbolic verification in ProVerif, network emulation in Mininet, and hardware experiments on Raspberry Pi and ESP32-C3. S2-Code achieves 100% session recovery after a catastrophic 50-count desynchronization where rolling codes fail. Under 30% packet loss, it sustains 60% success versus 20% for the rolling-code baseline (p < 10-8). A layered DoS defense—kernel-level rate limiting (nftables) plus an adaptive protocol mechanism—raises legitimate success from ≈ 17 % under flooding to ≈ 92.9 % under protocol-aware attack. The protocol has a small footprint (<8 KB flash, <4 KB RAM), low overhead (≈ 114 -byte packets, <17 ms latency), and scales to 100 concurrent devices in emulation. S2-Code offers a practical, robust middle ground between fragile rolling codes and heavyweight PKI for resource-constrained IoT.
denial-of-service (DoS) , IoT authentication , lightweight protocol , out-of-step recovery , robustness , rolling code , self-synchronization
Text of the article Перейти на текст статьи
Institute of Automation and Information Technology, Satbayev University, Almaty, 050013, Kazakhstan
Al-Farabi Kazakh National University, Higher School of Economics and Business, Almaty, 050040, Kazakhstan
Kyrgyzstan National University, Bishkek, 720033, Kyrgyzstan
Chongqing Vocational and Technical University of Mechatronics, Chongqing, 401120, China
School of Computer Science, Xi’an Shiyou University, Xi’an, 710065, China
Institute of Automation and Information Technology
Al-Farabi Kazakh National University
Kyrgyzstan National University
Chongqing Vocational and Technical University of Mechatronics
School of Computer Science
10 лет помогаем публиковать статьи Международный издатель
Книга Публикация научной статьи Волощук 2026 Book Publication of a scientific article 2026