An improved smart card based authentication scheme for session initiation protocol

被引:65
作者
Kumari, Saru [1 ]
Chaudhry, Shehzad Ashraf [2 ]
Wu, Fan [3 ]
Li, Xiong [4 ,5 ]
Farash, Mohammad Sabzinejad [6 ]
Khan, Muhammad Khurram [7 ]
机构
[1] Ch Charan Singh Univ, Dept Math, Meerut 250004, Uttar Pradesh, India
[2] Int Islamic Univ, Dept Comp Sci & Software Engn, Islamabad, Pakistan
[3] Xiamen Inst Technol, Dept Comp Sci & Engn, Xiamen 361021, Peoples R China
[4] Hunan Univ Sci & Technol, Sch Comp Sci & Engn, Xiangtan 411201, Peoples R China
[5] Nanjing Univ Informat Sci & Technol, Nanjing 210044, Jiangsu, Peoples R China
[6] Kharazmi Univ, Dept Math & Comp Sci, Tehran, Iran
[7] King Saud Univ, Ctr Excellence Informat Assurance CoEIA, Riyadh, Saudi Arabia
基金
中国国家自然科学基金;
关键词
Authentication; Security; Anonymity and privacy; Impersonation attack; Provable security; ProVerif; UNLINKABILITY;
D O I
10.1007/s12083-015-0409-0
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Sessioninitiation protocol (SIP) reformed the controlling routine of voice over Internet Protocol based communication over public channels. SIP is inherently insecure because of underlying open text architecture. A number of solutions are proposed to boost SIP security. Very recently Farash (Peer to Peer Netw. Appl. 1-10, 2014) proposed an enhanced protocol to improve the security of Tu et al.'s protocol (Peer to Peer Netw. Appl. 1-8, 2014). Further, Farash claimed his protocol to be secure against all known attacks. However, in this paper we show that Farash's protocol is insecure against impersonation attack, password guessing attack, lacks user anonymity and is vulnerable to session-specific temporary information attack. Further, we have proposed an upgraded protocol to enhance the security. The security and performance analysis shows that the proposed protocol reduced one point multiplication as compared with Farash's protocol, while resisting all known attacks. We have proved the security of proposed protocol using automated tool ProVerif.
引用
收藏
页码:92 / 105
页数:14
相关论文
共 50 条
[41]   Provably secure three-factor authentication and key agreement scheme for session initiation protocol [J].
Challa, Sravani ;
Das, Ashok Kumar ;
Kumari, Saru ;
Odelu, Vanga ;
Wu, Fan ;
Li, Xiong .
SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (18) :5412-5431
[42]   An enhanced password authentication scheme for session initiation protocol with perfect forward secrecy [J].
Qiu, Shuming ;
Xu, Guoai ;
Ahmad, Haseeb ;
Guo, Yanhui .
PLOS ONE, 2018, 13 (03)
[43]   An improved smart card based anonymous multi-server remote user authentication scheme [J].
Banerjee, Subhasish ;
Dutta, Manash Pratim ;
Bhunia, C.T. .
International Journal of Smart Home, 2015, 9 (05) :11-22
[44]   A Novel Authentication Scheme Based on Torus Automorphism for Smart Card [J].
Chang, Chin-Chen ;
Mao, Qian ;
Wu, Hsiao-Ling .
Smart Innovation, Systems and Technologies, 2013, 21 :53-60
[45]   A Comparative Analysis and Improvement of Smart Card based Authentication Scheme [J].
Panwar, Narendra ;
Rauthan, Manmohan Singh ;
Agarwal, Amit .
2016 NINTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2016, :345-348
[46]   Security Enhancements of Smart Card-Based Remote User Password Authentication Scheme with Session Key Agreement [J].
An, Young-Hwa .
2015 17TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT), 2015, :669-674
[47]   A Smart-Card-Based Remote User Authentication Protocol with Privacy Support [J].
Lu, Jian-Zhu ;
Deng, Shengyuan ;
Zhou, Jipeng ;
Fan, Xiuwei ;
Yang, Hao .
2012 13TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS, AND TECHNOLOGIES (PDCAT 2012), 2012, :96-101
[48]   Cryptanalysis and Improvement of a Smart Card Based Mutual Authentication Scheme in Cloud Computing [J].
Jiang, Qi ;
Li, Bingyan ;
Ma, Jianfeng ;
Tian, Youliang ;
Yang, Yuanyuan .
CLOUD COMPUTING AND SECURITY, ICCCS 2016, PT I, 2016, 10039 :311-321
[49]   A secure and robust elliptic curve cryptography-based mutual authentication scheme for session initiation protocol [J].
Nikooghadam, Mahdi ;
Amintoosi, Haleh .
SECURITY AND PRIVACY, 2020, 3 (01)
[50]   SAS-SIP: A secure authentication scheme based on ECC and a fuzzy extractor for session initiation protocol [J].
Maitra, Tanmoy ;
Giri, Debasis ;
Mohapatra, Ram N. .
CRYPTOLOGIA, 2019, 43 (03) :212-232