An improved and secure multiserver authentication scheme based on biometrics and smartcard

被引:26
作者
Kumar, Ashish [1 ]
Om, Hari [1 ]
机构
[1] Indian Inst Technol ISM, Dept Comp Sci & Engn, Dhanbad 826004, Jharkhand, India
关键词
Smartcard; Password; Security; Authentication; Multi-server; Biometric; ProVerif; KEY-AGREEMENT PROTOCOL; EFFICIENT; ROBUST; CARDS;
D O I
10.1016/j.dcan.2017.09.004
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
With the advancement in internet technologies, the number of servers has increased remarkably to provide more services to the end users. These services are provided over the public channels, which are insecure and susceptible to interception, modification, and deletion. To provide security, registered entities are authenticated and then a session key is established between them to communicate securely. The conventional schemes allow a user to access services only after their independent registration with each desired server in a multiserver system. Therefore, a user must possess multiple smartcards and memorize various identities and passwords for obtaining services from multiple servers. This has led to the adoption of multiserver authentication in which a user accesses services of multiple servers after registering himself at only one central authority. Recently, Kumar and Om discussed a scheme for multiserver environment by using smartcard. Since the user-memorized passwords are of low entropy, it is possible for an attacker to guess them. This paper uses biometric information of user to enhance the security of the scheme by Kumar and Om. Moreover, we conducted rigorous security analyses (informal and formal) in this study to prove the security of the proposed scheme against all known attacks. We also simulated our scheme by using the automated tool, ProVerif, to prove its secrecy and authentication properties. A comparative study of the proposed scheme with the existing related schemes shows its effectiveness.
引用
收藏
页码:27 / 38
页数:12
相关论文
共 44 条
[1]   Mobile values, new names, and secure communication [J].
Abadi, M ;
Fournet, C .
ACM SIGPLAN NOTICES, 2001, 36 (03) :104-115
[2]  
Abadi M, 2009, LECT NOTES COMPUT SC, V5643, P35, DOI 10.1007/978-3-642-02658-4_5
[3]  
[Anonymous], 2011, 2011365 CRYPT EPRINT
[4]  
Armando A, 2005, LECT NOTES COMPUT SC, V3576, P281
[5]   An enhanced remote user authentication scheme using smart cards [J].
Awasthi, AK ;
Lal, S .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (02) :583-586
[6]   A LOGIC OF AUTHENTICATION [J].
BURROWS, M ;
ABADI, M ;
NEEDHAM, RM .
PROCEEDINGS OF THE ROYAL SOCIETY OF LONDON SERIES A-MATHEMATICAL PHYSICAL AND ENGINEERING SCIENCES, 1989, 426 (1871) :233-271
[7]  
Chang CC, 2005, AINA 2005: 19TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 2, P257
[8]   An efficient and secure multi-server password authentication scheme using smart cards [J].
Chang, CC ;
Lee, JS .
2004 INTERNATIONAL CONFERENCE ON CYBERWORLDS, PROCEEDINGS, 2004, :417-422
[9]   An Untraceable Biometric-Based Multi-server Authenticated Key Agreement Protocol with Revocation [J].
Chang, Chin-Chen ;
Ngoc-Tu Nguyen .
WIRELESS PERSONAL COMMUNICATIONS, 2016, 90 (04) :1695-1715
[10]   Untraceable dynamic-identity-based remote user authentication scheme with verifiable password update [J].
Chang, Ya-Fen ;
Tai, Wei-Liang ;
Chang, Hung-Chin .
INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2014, 27 (11) :3430-3440