A Secure Biometrics-Based Multi-Server Authentication Protocol Using Smart Cards

被引:323
|
作者
Odelu, Vanga [1 ]
Das, Ashok Kumar [2 ]
Goswami, Adrijit [1 ]
机构
[1] IIT Kharagpur, Dept Math, Kharagpur 721302, W Bengal, India
[2] Int Inst Informat Technol, Ctr Secur Theory & Algorithm Res, Hyderabad 500032, Andhra Pradesh, India
关键词
Security; authentication; smart card; revocation and re-registration; BAN logic; AVISPA; KEY AGREEMENT; PASSWORD AUTHENTICATION; SCHEME; IMPROVEMENT; PRIVACY; CRYPTANALYSIS; EFFICIENT; ROBUST;
D O I
10.1109/TIFS.2015.2439964
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recently, in 2014, He and Wang proposed a robust and efficient multi-server authentication scheme using biometrics-based smart card and elliptic curve cryptography (ECC). In this paper, we first analyze He-Wang's scheme and show that their scheme is vulnerable to a known session-specific temporary information attack and impersonation attack. In addition, we show that their scheme does not provide strong user's anonymity. Furthermore, He-Wang's scheme cannot provide the user revocation facility when the smart card is lost/stolen or user's authentication parameter is revealed. Apart from these, He-Wang's scheme has some design flaws, such as wrong password login and its consequences, and wrong password update during password change phase. We then propose a new secure multi-server authentication protocol using biometric-based smart card and ECC with more security functionalities. Using the Burrows-Abadi-Needham logic, we show that our scheme provides secure authentication. In addition, we simulate our scheme for the formal security verification using the widely accepted and used automated validation of Internet security protocols and applications tool, and show that our scheme is secure against passive and active attacks. Our scheme provides high security along with low communication cost, computational cost, and variety of security features. As a result, our scheme is very suitable for battery-limited mobile devices as compared with He-Wang's scheme.
引用
收藏
页码:1953 / 1966
页数:14
相关论文
共 50 条
  • [41] A Multi-server Environment with Secure and Efficient Remote User Authentication Scheme Based on Dynamic ID Using Smart Cards
    Srinivas Jangirala
    Sourav Mukhopadhyay
    Ashok Kumar Das
    Wireless Personal Communications, 2017, 95 : 2735 - 2767
  • [42] A Multi-server Environment with Secure and Efficient Remote User Authentication Scheme Based on Dynamic ID Using Smart Cards
    Jangirala, Srinivas
    Mukhopadhyay, Sourav
    Das, Ashok Kumar
    WIRELESS PERSONAL COMMUNICATIONS, 2017, 95 (03) : 2735 - 2767
  • [43] A multi-server architecture authentication protocol using smart card
    Yu, Jie
    Pei, Qingqi
    PROCEEDINGS OF THE 2012 EIGHTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY (CIS 2012), 2012, : 511 - 515
  • [44] Cryptanalysis and improvement of a biometrics-based remote user authentication scheme using smart cards
    Li, Xiong
    Niu, Jian-Wei
    Ma, Jian
    Wang, Wen-Dong
    Liu, Cheng-Lian
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2011, 34 (01) : 73 - 79
  • [45] Provably Secure Multi-Server Authentication Protocol Using Fuzzy Commitment
    Barman, Subhas
    Das, Ashok Kumar
    Samanta, Debasis
    Chattopadhyay, Samiran
    Rodrigues, Joel J. P. C.
    Park, Youngho
    IEEE ACCESS, 2018, 6 : 38578 - 38594
  • [46] Cryptanalysis and improvement of a biometrics-based remote user authentication scheme using smart cards
    State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing 100876, China
    不详
    不详
    J Network Comput Appl, 1 (73-79):
  • [47] A Secure Privacy-Preserving Remote User Authentication Scheme Using Smart Cards for Multi-server Environment
    Tan, Zuowen
    INFORMATION-AN INTERNATIONAL INTERDISCIPLINARY JOURNAL, 2012, 15 (04): : 1547 - 1558
  • [48] Dual-Stage Biometrics-Based Password Authentication Scheme Using Smart Cards
    Boopathi, Mythili
    Aramudhan, M.
    CYBERNETICS AND SYSTEMS, 2017, 48 (05) : 415 - 435
  • [49] Key binding biometrics-based remote user authentication scheme using smart cards
    Al-Saggaf, Alawi A.
    IET BIOMETRICS, 2018, 7 (03) : 278 - 284
  • [50] A secure dynamic identity based authentication protocol for multi-server architecture
    Sood, Sandeep K.
    Sarje, Anil K.
    Singh, Kuldip
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2011, 34 (02) : 609 - 618