An Improved Authentication Scheme for Electroni Payment Systems in Global Mobility Networks

被引:5
作者
Heydari, Mohammad [1 ]
Sadough, S. Mohammad-Sajad [1 ]
Chaudhry, Shehzad Ashraf [2 ]
Farash, Mohammad Sabzinejad [3 ]
Aref, Mohammad Reza [4 ]
机构
[1] Shahid Beheshti Univ, Dept Elect Engn, Tehran, Iran
[2] Int Islamic Univ, Dept Comp Sci & Software Engn, Islamabad, Pakistan
[3] Kharazmi Univ, Dept Math & Comp Sci, Tehran, Iran
[4] Sharif Univ, Dept Elect Engn, Tehran, Iran
来源
INFORMATION TECHNOLOGY AND CONTROL | 2015年 / 44卷 / 04期
关键词
authenticated encryption; e-payment system; elliptic curve cryptography; digital signature; signcryption; SECURE; PROTOCOL; ENCRYPTION;
D O I
10.5755/j01.itc.44.4.9197
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently Yang et al. proposed an authenticated encryption scheme based on elliptic curve cryptography. The scheme reduced computation cost by excluding the construction of sender's digital signatures. Furthermore, Yang et al. presented an e-payment system based on their authenticated encryption scheme. They claimed their scheme to resist replay, man-in-middle, impersonation and identity theft attack, while providing confidentiality, authenticity, integrity and privacy protection. However, in this paper we show that Yang et al.'s both authenticated encryption scheme and e-payment system are vulnerable to impersonation attack. An attacker after acquiring the public key and identities of the participants can easily masquerade as legitimate user. Then, we presented improvements over both Yang et al.'s authenticated encryption and e-payment schemes. We analyze the security of proposed schemes using widespread automated tool ProVerif. The proposed schemes are more secure and lightweight as compared with Yang et al.'s schemes.
引用
收藏
页码:387 / 403
页数:17
相关论文
共 50 条
  • [1] An improved authentication with key agreement scheme on elliptic curve cryptosystem for global mobility networks
    Li, Xuelei
    Wen, Qiaoyan
    Zhang, Hua
    Jin, Zhengping
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2013, 23 (05) : 311 - 324
  • [2] User authentication scheme with anonymity, unlinkability and untrackability for global mobility networks
    Lee, Tian-Fu
    SECURITY AND COMMUNICATION NETWORKS, 2013, 6 (11) : 1404 - 1413
  • [4] Efficient privacy-preserving authentication scheme for roaming consumer in global mobility networks
    Ostad-Sharif, Arezou
    Babamohammadi, Abolfazl
    Abbasinezhad-Mood, Dariush
    Nikooghadam, Morteza
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2019, 32 (05)
  • [5] Fully Authentication Services Scheme for NFC Mobile Payment Systems
    Alshammari, Munefah
    Nashwan, Shadi
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2022, 32 (01) : 401 - 428
  • [6] A Secure and Effective Anonymous Authentication Scheme for Roaming Service in Global Mobility Networks
    Zhao, Dawei
    Peng, Haipeng
    Li, Lixiang
    Yang, Yixian
    WIRELESS PERSONAL COMMUNICATIONS, 2014, 78 (01) : 247 - 269
  • [7] A Secure Authentication Scheme with User Anonymity for Roaming Service in Global Mobility Networks
    Karuppiah, Marimuthu
    Saravanan, R.
    WIRELESS PERSONAL COMMUNICATIONS, 2015, 84 (03) : 2055 - 2078
  • [8] A Secure Anonymity Preserving Authentication Scheme for Roaming Service in Global Mobility Networks
    Odelu, Vanga
    Banerjee, Soumya
    Das, Ashok Kumar
    Chattopadhyay, Samiran
    Kumari, Saru
    Li, Xiong
    Goswami, Adrijit
    WIRELESS PERSONAL COMMUNICATIONS, 2017, 96 (02) : 2351 - 2387
  • [9] A secure lightweight two-factor authentication scheme in global mobility networks
    Madhusudhan, R.
    Suvidha, K. S.
    INTERNATIONAL JOURNAL OF SPACE-BASED AND SITUATED COMPUTING, 2019, 9 (02) : 109 - 123
  • [10] An Authentication Framework for Roaming Service in Global Mobility Networks
    Srinivas, Jangirala
    Mishra, Dheerendra
    Mukhopadhyay, Sourav
    Kumari, Saru
    Guleria, Vandana
    INFORMATION TECHNOLOGY AND CONTROL, 2019, 48 (01): : 129 - 145