Security Analysis and Enhancements of an Effective Biometric-Based Remote User Authentication Scheme Using Smart Cards

被引:55
作者
An, Younghwa [1 ]
机构
[1] Kangnam Univ, Div Comp & Media Informat Engn, Yongin 446702, Gyounggi Do, South Korea
来源
JOURNAL OF BIOMEDICINE AND BIOTECHNOLOGY | 2012年
关键词
PASSWORD AUTHENTICATION; EFFICIENT;
D O I
10.1155/2012/519723
中图分类号
Q81 [生物工程学(生物技术)]; Q93 [微生物学];
学科分类号
071005 ; 0836 ; 090102 ; 100705 ;
摘要
Recently, many biometrics-based user authentication schemes using smart cards have been proposed to improve the security weaknesses in user authentication system. In 2011, Das proposed an efficient biometric-based remote user authentication scheme using smart cards that can provide strong authentication and mutual authentication. In this paper, we analyze the security of Das's authentication scheme, and we have shown that Das's authentication scheme is still insecure against the various attacks. Also, we proposed the enhanced scheme to remove these security problems of Das's authentication scheme, even if the secret information stored in the smart card is revealed to an attacker. As a result of security analysis, we can see that the enhanced scheme is secure against the user impersonation attack, the server masquerading attack, the password guessing attack, and the insider attack and provides mutual authentication between the user and the server.
引用
收藏
页数:6
相关论文
共 15 条
[1]  
Baig A., 2009, INT J BIOSCIENCE BIO, V1, P47
[2]  
Bindu CS, 2008, INT J COMPUT SCI NET, V8, P62
[3]  
Chang C.C., 2010, INT J INTELLIGENT IN, V1, P41
[4]  
Das A. K., 2011, IET INFORM SECUR, V5, P541
[5]   A dynamic ID-based remote user authentication scheme [J].
Das, ML ;
Saxena, A ;
Gulati, VP .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (02) :629-631
[6]   A new remote user authentication scheme using smart cards [J].
Hwang, MS ;
Li, LH .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2000, 46 (01) :28-30
[7]  
Khan MK, 2006, LECT NOTES COMPUT SC, V3903, P260, DOI 10.1007/11689522_24
[8]  
Kocher P., 1999, Advances in Cryptology - CRYPTO'99. 19th Annual International Cryptology Conference. Proceedings, P388
[9]   Further cryptanalysis of fingerprint-based remote user authentication scheme using smartcards [J].
Ku, WC ;
Chang, ST ;
Chiang, MH .
ELECTRONICS LETTERS, 2005, 41 (05) :240-241
[10]   PASSWORD AUTHENTICATION WITH INSECURE COMMUNICATION [J].
LAMPORT, L .
COMMUNICATIONS OF THE ACM, 1981, 24 (11) :770-772