An Efficient and Provably Secure Anonymous User Authentication and Key Agreement for Mobile Cloud Computing

被引:34
作者
Mo, Jiaqing [1 ]
Hu, Zhongwang [1 ]
Chen, Hang [1 ]
Shen, Wei [1 ]
机构
[1] Zhaoqing Univ, Sch Comp Sci & Software, Zhaoqing, Peoples R China
基金
中国国家自然科学基金;
关键词
EXCHANGE PROTOCOL; ROAMING SERVICE; SCHEME;
D O I
10.1155/2019/4520685
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, due to the rapid development and wide deployment of handheld mobile devices, the mobile users begin to save their resources, access services, and run applications that are stored, deployed, and implemented in cloud computing which has huge storage space and massive computing capability with their mobile devices. However, the wireless channel is insecure and vulnerable to various attacks that pose a great threat to the transmission of sensitive data. Thus, the security mechanism of how the mobile devices and remote cloud server authenticate each other to create a secure session in mobile cloud computing environment has aroused the interest of researchers. In this paper, we propose an efficient and provably secure anonymous two-factor user authentication protocol for the mobile cloud computing environment. The proposed scheme not only provides mutual authentication between mobile devices and cloud computing but also fulfills the known security evaluation criteria. Moreover, utilization of ECC in our scheme reduces the computing cost for mobile devices that are computation capability limited and battery energy limited. In addition, the formal security proof is given to show that the proposed scheme is secure under random oracle model. Security analysis and performance comparisons indicate that the proposed scheme has reasonable computation cost and communication overhead at the mobile client side as well as the server side and is more efficient and more secure than the related competitive works.
引用
收藏
页数:12
相关论文
共 46 条
[1]   A more secure and privacy-aware anonymous user authentication scheme for distributed mobile cloud computing environments [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Biswas, G. P. ;
Giri, Debasis ;
Khan, Muhammad Khurram ;
Kumar, Neeraj .
SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (17) :4650-4666
[2]   Design of an anonymity-preserving three-factor authenticated key exchange protocol for wireless sensor networks [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Biswas, G. P. ;
Khan, Muhammad Khurram ;
Leng, Lu ;
Kumar, Neeraj .
COMPUTER NETWORKS, 2016, 101 :42-62
[3]  
[Anonymous], 2018, NIST Special Publication (SP), DOI [DOI 10.6028/NIST.SP.800-57PT1R4, DOI 10.6028/NIST.SP.800-57P1R3]
[4]  
[Anonymous], 1993, ACM CCS 1993, DOI DOI 10.1145/168588.168596
[5]   Notes on "Secure authentication scheme for IoT and cloud servers" [J].
Chang, Chin-Chen ;
Wu, Hsiao-Ling ;
Sun, Chin-Yu .
PERVASIVE AND MOBILE COMPUTING, 2017, 38 :275-278
[6]   An Improved Remote User Authentication Scheme Using Elliptic Curve Cryptography [J].
Chaudhry, Shehzad Ashraf ;
Naqvi, Husnain ;
Mahmood, Khalid ;
Ahmad, Hafiz Farooq ;
Khan, Muhammad Khurram .
WIRELESS PERSONAL COMMUNICATIONS, 2017, 96 (04) :5355-5373
[7]   Cryptanalysis and Improvement of an Improved Two Factor Authentication Protocol for Telecare Medical Information Systems [J].
Chaudhry, Shehzad Ashraf ;
Naqvi, Husnain ;
Shon, Taeshik ;
Sher, Muhammad ;
Farash, Mohammad Sabzinejad .
JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (06)
[8]   Two-Factor User Authentication in Wireless Sensor Networks [J].
Das, Manik Lal .
IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2009, 8 (03) :1086-1090
[9]   A secure and efficient identity-based authenticated key exchange protocol for mobile client-server networks [J].
Farash, Mohammad Sabzinejad ;
Attari, Mahmoud Ahmadian .
JOURNAL OF SUPERCOMPUTING, 2014, 69 (01) :395-411
[10]  
Gosney J., 2012, PASSW 2012 SEC C U O