Security Enhancement of an Improved Remote User Authentication Scheme with Key Agreement

被引:43
|
作者
Kaul, Sonam Devgan [1 ]
Awasthi, Amit K. [1 ]
机构
[1] Gautam Buddha Univ, Sch Appl Sci, Greater Noida 201306, India
关键词
Remote user authentication; Mutual authentication; Smart card; Key agreement; AVISPA; PASSWORD AUTHENTICATION;
D O I
10.1007/s11277-016-3297-6
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
In 2014, Kumari, Khan and Li proposed smart card based secure and robust remote user authentication scheme with key agreement and claimed that their scheme is suitable, secure and efficient for real life applications. But in this paper, we demonstrate that their proposed mechanism is completely insecure as an adversary can easily obtain not only the security parameters of the protocol but also obtains the common session key of future communication between user and the server. In addition, an adversary gets password of the registered user as well as secret key of the server. Thus collapses the entire system and authors claims are proven to be wrong. Hence, to remedy the identified security flaws and to ensure secure communication through an insecure channel, we propose an upgraded secure and efficient authentication protocol. Furthermore, we verify the security of our authentication protocol informally as well as formally via widely accepted OFMC and CL-AtSe back-ends of AVISPA tool against active and passive attacks.
引用
收藏
页码:621 / 637
页数:17
相关论文
共 50 条
  • [31] Further Improved Remote User Authentication Scheme
    Kim, Jung-Yoon
    Choi, Hyoung-Kee
    Copeland, John A.
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2011, E94A (06) : 1426 - 1433
  • [32] Security enhancement for the "simple authentication key agreement algorithm"
    Lin, IC
    Chang, CC
    Hwang, MS
    24TH ANNUAL INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COSPSAC 2000), 2000, 24 : 113 - 115
  • [33] A Security Enhancement and Proof for Authentication and Key Agreement (AKA)
    Kolesnikov, Vladimir
    SECURITY AND CRYPTOGRAPHY FOR NETWORKS, 2010, 6280 : 235 - 252
  • [34] Security and Efficiency Enhancement of Robust ID Based Mutual Authentication and Key Agreement Scheme Preserving User Anonymity in Mobile Networks
    Li, Chun-Ta
    Lee, Cheng-Chi
    Weng, Chi-Yao
    JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2018, 34 (01) : 155 - 170
  • [35] A novel remote user authentication and key agreement scheme for mobile client-server environment
    Sun, Haiyan
    Wen, Qiaoyan
    Zhang, Hua
    Jin, Zhengping
    APPLIED MATHEMATICS & INFORMATION SCIENCES, 2013, 7 (04): : 1365 - 1374
  • [36] Applying biometrics to design three-factor remote user authentication scheme with key agreement
    Li, Xiong
    Niu, Jianwei
    Wang, Zhibo
    Chen, Caisen
    SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (10) : 1488 - 1497
  • [37] Security Enhancement on the Efficient and Complete Remote User Authentication Scheme using smart Cards
    Lee, Young Sil
    Kim, Tae Yong
    Lee, Hoon Jae
    2011 6TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCES AND CONVERGENCE INFORMATION TECHNOLOGY (ICCIT), 2012, : 702 - 706
  • [38] Robust biometrics based three-factor remote user authentication scheme with key agreement
    Li, Xiong
    Niu, Jianwei
    Khan, Muhammad Khurram
    Liao, Junguo
    2013 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2013, : 105 - 110
  • [39] Security Enhancement on an Improvement on Two Remote User Authentication Scheme Using Smart Cards
    Hsiang, HanCheng
    Chen, TienHo
    Shih, WeiKuan
    COMMUNICATION AND NETWORKING, 2009, 56 : 65 - +
  • [40] Robust three-factor remote user authentication scheme with key agreement for multimedia systems
    Li, Xiong
    Niu, Jianwei
    Khan, Muhammad Khurram
    Liao, Junguo
    Zhao, Xiaoke
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (13) : 1916 - 1927