An efficient and secure multi-server authentication scheme with key agreement

被引:54
作者
Tsaur, Woei-Jiunn [1 ]
Li, Jia-Hong [2 ]
Lee, Wei-Bin [2 ]
机构
[1] Da Yeh Univ, Dept Informat Management, Changhua 51591, Taiwan
[2] Feng Chia Univ, Dept Informat Engn & Comp Sci, Taichung 40724, Taiwan
关键词
Authentication; Key exchange; Information security; Computer networks; Smart card; REMOTE PASSWORD AUTHENTICATION; SMART CARD; ANONYMITY; ROBUST;
D O I
10.1016/j.jss.2011.10.049
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Remote user authentication is used to validate the legitimacy of a remote log-in user. Due to the rapid growth of computer networks, many network environments have been becoming multi-server based. Recently, much research has been focused on proposing remote password authentication schemes based on smart cards for securing multi-server environments. Each of these schemes used either a nonce or a timestamp technique to prevent the replay attack. However, using the nonce technique to withstand the replay attack is potentially susceptible to the man-in-the-middle attack. Alternatively, when employing the timestamp method to secure remote password authentication, it will require the cost of implementing clock synchronization. In order to solve the above two issues, this paper proposes a self-verified timestamp technique to help the smart-card-based authentication scheme not only effectively achieve password-authenticated key agreement but also avoid the difficulty of implementing clock synchronization in multi-server environments. A secure authenticated key agreement should accomplish both mutual authentication and session key establishment. Therefore, in this paper we further give the formal proof on the execution of the proposed authenticated key agreement scheme. (C) 2011 Elsevier Inc. All rights reserved.
引用
收藏
页码:876 / 882
页数:7
相关论文
共 33 条
[21]   A novel privacy preserving authentication and access control scheme for pervasive computing environments [J].
Ren, Kui ;
Lou, Wenjing ;
Kim, Kwangjo ;
Deng, Robert .
IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2006, 55 (04) :1373-1384
[22]   Improvements of Juang et al.'s Pas sword-Authenticated Key Agreement Scheme Using Smart Cards [J].
Sun, Da-Zhi ;
Huai, Jin-Peng ;
Sun, Ji-Zhou ;
Li, Jian-Xin ;
Zhang, Jia-Wan ;
Feng, Zhi-Yong .
IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2009, 56 (06) :2284-2291
[23]   An efficient remote use authentication scheme using smart cards [J].
Sun, HM .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2000, 46 (04) :958-961
[24]   Remote password authentication scheme based on cross-product [J].
Tan, K ;
Zhu, H .
COMPUTER COMMUNICATIONS, 1999, 22 (04) :390-393
[26]   An enhanced user authentication scheme for multi-server Internet services [J].
Tsaur, WJ ;
Wu, CC ;
Lee, WB .
APPLIED MATHEMATICS AND COMPUTATION, 2005, 170 (01) :258-266
[27]   A smart card-based remote scheme for password authentication in multi-server Internet services [J].
Tsaur, WJ ;
Wu, CC ;
Lee, WB .
COMPUTER STANDARDS & INTERFACES, 2004, 27 (01) :39-51
[28]   Robust one-time password authentication scheme using smart card for home network environment [J].
Vaidya, Binod ;
Park, Jong Hyuk ;
Yeo, Sang-Soo ;
Rodrigues, Joel J. P. C. .
COMPUTER COMMUNICATIONS, 2011, 34 (03) :326-336
[29]   User Authentication Scheme with Privacy-Preservation for Multi-Server Environment [J].
Wang, Ren-Chiun ;
Juang, Wen-Shenq ;
Lei, Chin-Laung .
IEEE COMMUNICATIONS LETTERS, 2009, 13 (02) :157-159
[30]  
Wang SJ, 1996, COMPUT SECUR, V15, P231, DOI 10.1016/0167-4048(96)00005-3