A lightweight anonymous authentication scheme for secure cloud computing services

被引:11
作者
Hammami, Hamza [1 ]
Ben Yahia, Sadok [1 ,2 ]
Obaidat, Mohammad S. [3 ,4 ,5 ]
机构
[1] Univ Tunis El Manar, Fac Sci Tunis, LIPAH LR11ES14, Tunis 2092, Tunisia
[2] Tallinn Univ Technol, Dept Software Sci, Akad Tee 15a, EE-12618 Tallinn, Estonia
[3] Univ Sharjah, Coll Comp & Informat, Sharjah, U Arab Emirates
[4] Univ Jordan, King Abdullah II Sch Informat Technol, Amman, Jordan
[5] Univ Sci & Technol Beijing, Beijing, Peoples R China
关键词
Cloud computing; Security; Attacks; Privacy; Anonymous; Authentication; KEY EXCHANGE PROTOCOL;
D O I
10.1007/s11227-020-03313-y
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing represents the latest technology that has revolutionized the world of business. It is a promising solution giving companies the possibility of remotely storing their data and accessing services whenever they are needed and at a lower cost. However, outsourcing IT resources also brings risks, especially for sensitive information in terms of security and privacy, since all data and resources stored in the cloud are managed and controlled by cloud service providers. On the other hand, cloud users would like cloud service providers not to know what services being accessed and how often they are using them. Therefore, designing mechanisms to protect privacy is a major challenge. One promising research area is via authentication mechanisms, which has attracted many researchers in this delicate subject. For this, several solutions have been devised and published recently to tackle this problem. Nevertheless, these solutions often suffer from different types of attacks, high computing and communication costs, and the use of complex key management schemes. To address these shortcomings, we propose an approach that ensures the optimal preservation of the privacy of cloud users to protect their personal data including identities. The suggested approach gives the cloud user the ability to access and use the services provided by cloud service providers anonymously without the providers of those services knowing their identity. We demonstrate the superiority of our proposed approach over several anonymous authentication solutions in terms of computation and communication costs.
引用
收藏
页码:1693 / 1713
页数:21
相关论文
共 26 条
[1]   Notes on "Secure authentication scheme for IoT and cloud servers" [J].
Chang, Chin-Chen ;
Wu, Hsiao-Ling ;
Sun, Chin-Yu .
PERVASIVE AND MOBILE COMPUTING, 2017, 38 :275-278
[2]   An Improved Remote User Authentication Scheme Using Elliptic Curve Cryptography [J].
Chaudhry, Shehzad Ashraf ;
Naqvi, Husnain ;
Mahmood, Khalid ;
Ahmad, Hafiz Farooq ;
Khan, Muhammad Khurram .
WIRELESS PERSONAL COMMUNICATIONS, 2017, 96 (04) :5355-5373
[3]   Cryptanalysis and Improvement of an Improved Two Factor Authentication Protocol for Telecare Medical Information Systems [J].
Chaudhry, Shehzad Ashraf ;
Naqvi, Husnain ;
Shon, Taeshik ;
Sher, Muhammad ;
Farash, Mohammad Sabzinejad .
JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (06)
[4]  
CHIA WY, 2009, THESIS
[5]  
DJELLALBIA A, 2016, THESIS
[6]   A secure and efficient identity-based authenticated key exchange protocol for mobile client-server networks [J].
Farash, Mohammad Sabzinejad ;
Attari, Mahmoud Ahmadian .
JOURNAL OF SUPERCOMPUTING, 2014, 69 (01) :395-411
[7]  
*FUJ, 2010, PERS DAT CLOUD GLOB
[8]   Security Issues In Cloud Computing And Associated Alleviation Approaches [J].
Hammami, Hamza ;
Brahmi, Hanen ;
Brahmi, Imen ;
Ben Yahia, Sadok .
2016 12TH INTERNATIONAL CONFERENCE ON SIGNAL-IMAGE TECHNOLOGY & INTERNET-BASED SYSTEMS (SITIS), 2016, :758-765
[9]  
Jiang L, 2013, IEEE VEHICLE POWER, P21
[10]  
Karajeh H., 2020, Proceedings of the 23rd IBIMA Conference Vision, P1