Cryptanalysis and improvement of a biometric-based remote user authentication protocol usable in a multiserver environment

被引:18
作者
Chandrakar, Preeti [1 ]
Om, Hari [1 ]
机构
[1] Indian Sch Mines, Indian Inst Technol, Dept Comp Sci & Engn, Dhanbad 826004, Bihar, India
关键词
KEY-AGREEMENT PROTOCOL; SMART-CARD; ANONYMOUS AUTHENTICATION; SCHEME; SECURE; ENHANCEMENT; PASSWORD;
D O I
10.1002/ett.3200
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Recently, Amin and Biswas have discussed a bilinear pairing-based three-factor remote user authentication protocol, claiming it to be secured against various attacks. We scrutinize this protocol and find that it is vulnerable to identity guessing attack, password guessing attack, user untraceability attack, user-server impersonation attack, new smart card issue attack, and privileged insider attack. In this paper, we propose an elliptic curve cryptography and biometric-based remote user authentication protocol for a multiserver environment by overcoming these drawbacks. We conduct its informal and formal security analysis to show that it resists all known security attacks. The Burrows-Abadi-Needham (BAN) logic verifies that our protocol facilitates mutual authentication and session key agreement securely. We simulate it using the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool to certify that it can be protected from passive and active threats, including replay and man-in-the-middle attacks. Furthermore, the proposed protocol provides more security attributes and better complexity in terms of smart card storage cost, computation cost, estimated time, and communication cost, as compared with the related existing protocols.
引用
收藏
页数:26
相关论文
共 68 条
[1]   A more secure and privacy-aware anonymous user authentication scheme for distributed mobile cloud computing environments [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Biswas, G. P. ;
Giri, Debasis ;
Khan, Muhammad Khurram ;
Kumar, Neeraj .
SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (17) :4650-4666
[2]   Cryptanalysis and Enhancement of Anonymity Preserving Remote User Mutual Authentication and Session Key Agreement Scheme for E-Health Care Systems [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Biswas, G. P. ;
Khan, Muhammad Khurram ;
Li, Xiong .
JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (11)
[3]   Design and Analysis of Bilinear Pairing Based Mutual Authentication and Key Agreement Protocol Usable in Multi-server Environment [J].
Amin, Ruhul ;
Biswas, G. P. .
WIRELESS PERSONAL COMMUNICATIONS, 2015, 84 (01) :439-462
[4]  
[Anonymous], PLOS ONE
[5]  
[Anonymous], 2016, FUTUR GENER COMPUT S
[6]  
[Anonymous], AVISPA WEB TOOL
[7]  
[Anonymous], FUTURE GENER COMPUT
[8]  
[Anonymous], 2016, IEEE T DEPENDABLE SE
[9]  
[Anonymous], 2016, IEEE T DEPENDABLE SE
[10]  
[Anonymous], ANNUAL INTERNATIONAL