Security Enhancements for a Relay Chain-Based Cross-Chain Identity Authentication Protocol
This paper identifies a critical flaw in a chaotic map–based multi-factor authentication protocol for UWSNs: its session keys depend on static long-term secrets, violating forward and backward secrecy if devices are compromised. We formally prove that an attacker can recover all past and future keys under such compromise. To fix this, we propose an enhanced key exchange using ephemeral chaotic-map–derived secrets, ensuring session keys remain secure even with long-term credential leakage. The improved protocol maintains comparable performance while achieving essential security properties.