An improved and secure multiserver authentication scheme based on biometrics and smartcard

被引:26
作者
Kumar, Ashish [1 ]
Om, Hari [1 ]
机构
[1] Indian Inst Technol ISM, Dept Comp Sci & Engn, Dhanbad 826004, Jharkhand, India
关键词
Smartcard; Password; Security; Authentication; Multi-server; Biometric; ProVerif; KEY-AGREEMENT PROTOCOL; EFFICIENT; ROBUST; CARDS;
D O I
10.1016/j.dcan.2017.09.004
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
With the advancement in internet technologies, the number of servers has increased remarkably to provide more services to the end users. These services are provided over the public channels, which are insecure and susceptible to interception, modification, and deletion. To provide security, registered entities are authenticated and then a session key is established between them to communicate securely. The conventional schemes allow a user to access services only after their independent registration with each desired server in a multiserver system. Therefore, a user must possess multiple smartcards and memorize various identities and passwords for obtaining services from multiple servers. This has led to the adoption of multiserver authentication in which a user accesses services of multiple servers after registering himself at only one central authority. Recently, Kumar and Om discussed a scheme for multiserver environment by using smartcard. Since the user-memorized passwords are of low entropy, it is possible for an attacker to guess them. This paper uses biometric information of user to enhance the security of the scheme by Kumar and Om. Moreover, we conducted rigorous security analyses (informal and formal) in this study to prove the security of the proposed scheme against all known attacks. We also simulated our scheme by using the automated tool, ProVerif, to prove its secrecy and authentication properties. A comparative study of the proposed scheme with the existing related schemes shows its effectiveness.
引用
收藏
页码:27 / 38
页数:12
相关论文
共 44 条
[31]   An Improved Anonymous Multi-Server Authenticated Key Agreement Scheme Using Smart Cards and Biometrics [J].
Lin, Hao ;
Wen, Fengtong ;
Du, Chunxia .
WIRELESS PERSONAL COMMUNICATIONS, 2015, 84 (04) :2351-2362
[32]  
Lu Y., 2015, SECUR COMMUN NETW, V8
[33]   Examining smart-card security under the threat of power analysis attacks [J].
Messerges, TS ;
Dabbish, EA ;
Sloan, RH .
IEEE TRANSACTIONS ON COMPUTERS, 2002, 51 (05) :541-552
[34]   A secure user anonymity-preserving biometric-based multi-server authenticated key agreement scheme using smart cards [J].
Mishra, Dheerendra ;
Das, Ashok Kumar ;
Mukhopadhyay, Sourav .
EXPERT SYSTEMS WITH APPLICATIONS, 2014, 41 (18) :8129-8143
[35]   A Secure Biometrics-Based Multi-Server Authentication Protocol Using Smart Cards [J].
Odelu, Vanga ;
Das, Ashok Kumar ;
Goswami, Adrijit .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2015, 10 (09) :1953-1966
[36]   An Anonymous Authentication with Key-Agreement Protocol for Multi-Server Architecture Based on Biometrics and Smartcards [J].
Reddy, Alavalapati Goutham ;
Das, Ashok Kumar ;
Yoon, Eun-Jun ;
Yoo, Kee-Young .
KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2016, 10 (07) :3371-3396
[37]   An Enhanced Biometric Based Authentication with Key-Agreement Protocol for Multi-Server Architecture Based on Elliptic Curve Cryptography [J].
Reddy, Alavalapati Goutham ;
Das, Ashok Kumar ;
Odelu, Vanga ;
Yoo, Kee-Young .
PLOS ONE, 2016, 11 (05)
[38]   A Simple and Generic Construction of Authenticated Encryption with Associated Data [J].
Sarkar, Palash .
ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2010, 13 (04)
[39]   New biometrics-based authentication scheme for multi-server environment in critical systems [J].
Shen, Han ;
Gao, Chongzhi ;
He, Debiao ;
Wu, Libing .
JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2015, 6 (06) :825-834
[40]   Some observations on the theory of cryptographic hash functions [J].
Stinson, DR .
DESIGNS CODES AND CRYPTOGRAPHY, 2006, 38 (02) :259-277