A secure and robust anonymous three-factor remote user authentication scheme for multi-server environment using ECC

被引:61
作者
Chandrakar, Preeti [1 ]
Om, Hari [1 ]
机构
[1] Indian Sch Mines, Indian Inst Technol, Dept Comp Sci & Engn, Dhanbad 826004, Jharkhand, India
关键词
Authentication; BAN logic; ECC; Multi-server; Three-factor; CERTIFIED PUBLIC KEYS; CRYPTANALYSIS; PROTOCOL; ENHANCEMENT; IMPROVEMENT;
D O I
10.1016/j.comcom.2017.05.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the rapid growth of the computer and the Internet technology, various types of services are provided through the Internet such as e-banking, e-rail, e-commerce, online game, etc. Today, they have become an important part of our lives and make life very convenient. However, most of these applications/services operate over an insecure channel therefore authentication is required before permitting the remote access of those services. In this paper, we propose a secure anonymous three-factor based remote user authentication scheme for multi-server environment using ECC. We show that the proposed scheme is accurate and provides mutual authentication and session key agreement securely on the basis of BAN logic. Its formal security analysis, using Random Oracle Model, shows that an attacker cannot retrieve the backbone parameters such as user identity, password, secret keys, and session key. Using informal security analysis, we prove that our scheme defends against various security pitfalls. Additionally, we compare our scheme with other surviving relevant schemes and the comparative results show that our scheme is efficient in terms of computation cost, communication cost, smart card storage cost and estimated time. Specially, the proposed scheme is not only secure against various security threats, but it also facilitates an accurate login phase, robust authentication phase and user friendly password change phase. (C) 2017 Elsevier B.V. All rights reserved.
引用
收藏
页码:26 / 34
页数:9
相关论文
共 34 条
[1]   A secure and robust three-factor based authentication scheme using RSA cryptosystem [J].
Ali, Rifaqat ;
Pal, Arup Kumar .
International Journal of Business Data Communications and Networking, 2017, 13 (01) :74-84
[2]  
Amin Ruhul, 2016, International Journal of Network Security, V18, P172
[3]   A robust and anonymous patient monitoring system using wireless medical sensor networks [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Biswas, G. P. ;
Khan, Muhammad Khurram ;
Kumar, Neeraj .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 80 :483-495
[4]   Design of an anonymity-preserving three-factor authenticated key exchange protocol for wireless sensor networks [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Biswas, G. P. ;
Khan, Muhammad Khurram ;
Leng, Lu ;
Kumar, Neeraj .
COMPUTER NETWORKS, 2016, 101 :42-62
[5]   Cryptanalysis and Enhancement of Anonymity Preserving Remote User Mutual Authentication and Session Key Agreement Scheme for E-Health Care Systems [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Biswas, G. P. ;
Khan, Muhammad Khurram ;
Li, Xiong .
JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (11)
[6]   Design and Analysis of Bilinear Pairing Based Mutual Authentication and Key Agreement Protocol Usable in Multi-server Environment [J].
Amin, Ruhul ;
Biswas, G. P. .
WIRELESS PERSONAL COMMUNICATIONS, 2015, 84 (01) :439-462
[7]   A Secure Three-Factor User Authentication and Key Agreement Protocol for TMIS With User Anonymity [J].
Amin, Ruhul ;
Biswas, G. P. .
JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (08)
[8]  
[Anonymous], J MED SYSTEMS
[9]  
[Anonymous], ARABIAN J SCI ENG
[10]  
[Anonymous], 2015, J MED SYST, DOI DOI 10.1007/s10916-014-0145-7