A Secure Biometrics-Based Multi-Server Authentication Protocol Using Smart Cards

被引:324
作者
Odelu, Vanga [1 ]
Das, Ashok Kumar [2 ]
Goswami, Adrijit [1 ]
机构
[1] IIT Kharagpur, Dept Math, Kharagpur 721302, W Bengal, India
[2] Int Inst Informat Technol, Ctr Secur Theory & Algorithm Res, Hyderabad 500032, Andhra Pradesh, India
关键词
Security; authentication; smart card; revocation and re-registration; BAN logic; AVISPA; KEY AGREEMENT; PASSWORD AUTHENTICATION; SCHEME; IMPROVEMENT; PRIVACY; CRYPTANALYSIS; EFFICIENT; ROBUST;
D O I
10.1109/TIFS.2015.2439964
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recently, in 2014, He and Wang proposed a robust and efficient multi-server authentication scheme using biometrics-based smart card and elliptic curve cryptography (ECC). In this paper, we first analyze He-Wang's scheme and show that their scheme is vulnerable to a known session-specific temporary information attack and impersonation attack. In addition, we show that their scheme does not provide strong user's anonymity. Furthermore, He-Wang's scheme cannot provide the user revocation facility when the smart card is lost/stolen or user's authentication parameter is revealed. Apart from these, He-Wang's scheme has some design flaws, such as wrong password login and its consequences, and wrong password update during password change phase. We then propose a new secure multi-server authentication protocol using biometric-based smart card and ECC with more security functionalities. Using the Burrows-Abadi-Needham logic, we show that our scheme provides secure authentication. In addition, we simulate our scheme for the formal security verification using the widely accepted and used automated validation of Internet security protocols and applications tool, and show that our scheme is secure against passive and active attacks. Our scheme provides high security along with low communication cost, computational cost, and variety of security features. As a result, our scheme is very suitable for battery-limited mobile devices as compared with He-Wang's scheme.
引用
收藏
页码:1953 / 1966
页数:14
相关论文
共 50 条
  • [11] Chen TY, 2014, 2014 IEEE WORKSHOP ON ELECTRONICS, COMPUTER AND APPLICATIONS, P771, DOI 10.1109/IWECA.2014.6845736
  • [12] Towards secure and efficient user authentication scheme using smart card for multi-server environments
    Chen, Te-Yu
    Lee, Cheng-Chi
    Hwang, Min-Shiang
    Jan, Jinn-Ke
    [J]. JOURNAL OF SUPERCOMPUTING, 2013, 66 (02) : 1008 - 1032
  • [13] Analysis and improvement on an efficient biometric-based remote user authentication scheme using smart cards
    Das, A. K.
    [J]. IET INFORMATION SECURITY, 2011, 5 (03) : 145 - 151
  • [14] Dodis Y, 2004, LECT NOTES COMPUT SC, V3027, P523
  • [15] ON THE SECURITY OF PUBLIC KEY PROTOCOLS
    DOLEV, D
    YAO, AC
    [J]. IEEE TRANSACTIONS ON INFORMATION THEORY, 1983, 29 (02) : 198 - 208
  • [16] Privacy-Preserving Universal Authentication Protocol for Wireless Communications
    He, Daojing
    Bu, Jiajun
    Chan, Sammy
    Chen, Chun
    Yin, Mingjian
    [J]. IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2011, 10 (02) : 431 - 436
  • [17] Improvement of the secure dynamic ID based remote user authentication scheme for multi-server environment
    Hsiang, Han-Cheng
    Shih, Wei-Kuan
    [J]. COMPUTER STANDARDS & INTERFACES, 2009, 31 (06) : 1118 - 1123
  • [18] Further Observations on Smart-Card-Based Password-Authenticated Key Agreement in Distributed Systems
    Huang, Xinyi
    Chen, Xiaofeng
    Li, Jin
    Xiang, Yang
    Xu, Li
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2014, 25 (07) : 1767 - 1775
  • [19] A Generic Framework for Three-Factor Authentication: Preserving Security and Privacy in Distributed Systems
    Huang, Xinyi
    Xiang, Yang
    Chonka, Ashley
    Zhou, Jianying
    Deng, Robert H.
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2011, 22 (08) : 1390 - 1397
  • [20] Biometric identification
    Jain, A
    Hong, L
    Pankanti, S
    [J]. COMMUNICATIONS OF THE ACM, 2000, 43 (02) : 90 - 98