Security Enhancement of an Improved Remote User Authentication Scheme with Key Agreement

被引:43
|
作者
Kaul, Sonam Devgan [1 ]
Awasthi, Amit K. [1 ]
机构
[1] Gautam Buddha Univ, Sch Appl Sci, Greater Noida 201306, India
关键词
Remote user authentication; Mutual authentication; Smart card; Key agreement; AVISPA; PASSWORD AUTHENTICATION;
D O I
10.1007/s11277-016-3297-6
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
In 2014, Kumari, Khan and Li proposed smart card based secure and robust remote user authentication scheme with key agreement and claimed that their scheme is suitable, secure and efficient for real life applications. But in this paper, we demonstrate that their proposed mechanism is completely insecure as an adversary can easily obtain not only the security parameters of the protocol but also obtains the common session key of future communication between user and the server. In addition, an adversary gets password of the registered user as well as secret key of the server. Thus collapses the entire system and authors claims are proven to be wrong. Hence, to remedy the identified security flaws and to ensure secure communication through an insecure channel, we propose an upgraded secure and efficient authentication protocol. Furthermore, we verify the security of our authentication protocol informally as well as formally via widely accepted OFMC and CL-AtSe back-ends of AVISPA tool against active and passive attacks.
引用
收藏
页码:621 / 637
页数:17
相关论文
共 50 条
  • [1] Security Enhancement of an Improved Remote User Authentication Scheme with Key Agreement
    Sonam Devgan Kaul
    Amit K. Awasthi
    Wireless Personal Communications, 2016, 89 : 621 - 637
  • [2] An improved remote user authentication scheme with key agreement
    Kumari, Saru
    Khan, Muhammad Khurram
    Li, Xiong
    COMPUTERS & ELECTRICAL ENGINEERING, 2014, 40 (06) : 1997 - 2012
  • [3] Cryptanalysis of Remote User Authentication Scheme with key agreement
    Madhusudan, R.
    Valiveti, Annapurna
    2015 2ND INTERNATIONAL CONFERENCE ON COMPUTER, COMMUNICATIONS, AND CONTROL TECHNOLOGY (I4CT), 2015,
  • [4] Improved Biometrics-Based Remote User Authentication Scheme with Session Key Agreement
    An, Younghwa
    COMPUTER APPLICATIONS FOR GRAPHICS, GRID COMPUTING, AND INDUSTRIAL ENVIRONMENT, 2012, 351 : 307 - 315
  • [5] An Improved Anonymous Remote user Authentication Scheme with Key Agreement based on Dynamic Identity
    Shi, Yajuan
    Shen, Han
    Zhang, Yuanyuan
    Chen, Jianhua
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (05): : 255 - 268
  • [6] An improved dynamic ID-based remote user authentication with key agreement scheme
    Wen, Fengtong
    Li, Xuelei
    COMPUTERS & ELECTRICAL ENGINEERING, 2012, 38 (02) : 381 - 387
  • [7] An Improved Dynamic ID-Based Remote User Authentication with Key Agreement Scheme
    Qu, Juan
    Zou, Li-Min
    JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING, 2013, 2013
  • [8] An Improved User Authentication and Key Agreement Scheme Providing User Anonymity
    Ya-Fen Chang and Pei-Yu Chang Department of Computer Science and Information Engineering
    Journal of Electronic Science and Technology, 2011, 9 (04) : 352 - 358
  • [9] Improved security enhancement for a dynamic ID-based remote user authentication scheme
    School of Electronics and Information Engineering, Beijing University of Aeronautics and Astronautics, Beijing 100083, China
    Beijing Hangkong Hangtian Daxue Xuebao, 2007, 5 (565-567+621):
  • [10] Security Improvements of Dynamic ID-based Remote User Authentication Scheme with Session Key Agreement
    An, Young-Hwa
    2013 15TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT), 2013, : 1072 - 1076