Secure two-factor lightweight authentication protocol using self-certified public key cryptography for multi-server 5G networks

被引:50
作者
ul Haq, Inam [1 ]
Wang, Jian [1 ]
Zhu, Youwen [1 ]
机构
[1] Nanjing Univ Aeronaut & Astronaut NUAA, Coll Comp Sci & Technol, Nanjing 210016, Peoples R China
关键词
Multi-server architecture; Crypt-analysis; User impersonation attack; Self-certified public key; Light weight; AGREEMENT SCHEME; CHAOTIC MAP; EFFICIENT; ARCHITECTURE; ENVIRONMENT; BIOMETRICS; DESIGN;
D O I
10.1016/j.jnca.2020.102660
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Recently Ying and Nayak proposed a multi-server supported lightweight authentication protocol for 5G networks and confirmed the security of their protocol against all prominent attacks. Nevertheless, this paper will show certain shortcomings in their protocol, like vulnerability against identity guessing, password guessing, and user impersonation attacks. Additionally, it lacks in rendering strong user anonymity and truly two-factor security. Following the crypt-analysis, we propose an improved multi-server authentication protocol, that resists all recognized attacks, including these traps. The formal analysis using broadly accepted BAN-logic assures that the proposed protocol provides mutual authentication among the user and service-providing server. Additionally, the automated verification using the "Automated Validation of Internet Security Protocols and Applications" (AVISPA) tool asserts that improved protocol is safe toward active attacks. The performance comparison with the Ying-Nayak's protocol is evident that the proposed protocol is efficient concerning computational complexity and communication costs.
引用
收藏
页数:11
相关论文
共 52 条
  • [1] Design and Analysis of Bilinear Pairing Based Mutual Authentication and Key Agreement Protocol Usable in Multi-server Environment
    Amin, Ruhul
    Biswas, G. P.
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2015, 84 (01) : 439 - 462
  • [2] [Anonymous], 1991, P EURO CRYPTO
  • [3] [Anonymous], 2016, 8 INT C EV INT BARC
  • [4] Barker E., 2016, RECOMMENDATION KEY 1 80057 SP US NAT I ST, V800-57
  • [5] Provably Secure Multi-Server Authentication Protocol Using Fuzzy Commitment
    Barman, Subhas
    Das, Ashok Kumar
    Samanta, Debasis
    Chattopadhyay, Samiran
    Rodrigues, Joel J. P. C.
    Park, Youngho
    [J]. IEEE ACCESS, 2018, 6 : 38578 - 38594
  • [6] BURROWS M, 1990, ACM T COMPUT SYST, V8, P18, DOI [10.1145/77648.77649, 10.1145/74851.74852]
  • [7] A secure and robust anonymous three-factor remote user authentication scheme for multi-server environment using ECC
    Chandrakar, Preeti
    Om, Hari
    [J]. COMPUTER COMMUNICATIONS, 2017, 110 : 26 - 34
  • [8] Secure Biometric-Based Authentication Scheme Using Chebyshev Chaotic Map for Multi-Server Environment
    Chatterjee, Santanu
    Roy, Sandip
    Das, Ashok Kumar
    Chattopadhyay, Samiran
    Kumar, Neeraj
    Vasilakos, Athanasios V.
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2018, 15 (05) : 824 - 839
  • [9] A two-factor authentication scheme with anonymity for multi-server environments
    Chen, Chi-Tung
    Lee, Cheng-Chi
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (08) : 1608 - 1625
  • [10] An anonymous multi-server authenticated key agreement scheme based on trust computing using smart cards and biometrics
    Chuang, Ming-Chin
    Chen, Meng Chang
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2014, 41 (04) : 1411 - 1418