Security Enhancement of an Improved Remote User Authentication Scheme with Key Agreement

被引:43
|
作者
Kaul, Sonam Devgan [1 ]
Awasthi, Amit K. [1 ]
机构
[1] Gautam Buddha Univ, Sch Appl Sci, Greater Noida 201306, India
关键词
Remote user authentication; Mutual authentication; Smart card; Key agreement; AVISPA; PASSWORD AUTHENTICATION;
D O I
10.1007/s11277-016-3297-6
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
In 2014, Kumari, Khan and Li proposed smart card based secure and robust remote user authentication scheme with key agreement and claimed that their scheme is suitable, secure and efficient for real life applications. But in this paper, we demonstrate that their proposed mechanism is completely insecure as an adversary can easily obtain not only the security parameters of the protocol but also obtains the common session key of future communication between user and the server. In addition, an adversary gets password of the registered user as well as secret key of the server. Thus collapses the entire system and authors claims are proven to be wrong. Hence, to remedy the identified security flaws and to ensure secure communication through an insecure channel, we propose an upgraded secure and efficient authentication protocol. Furthermore, we verify the security of our authentication protocol informally as well as formally via widely accepted OFMC and CL-AtSe back-ends of AVISPA tool against active and passive attacks.
引用
收藏
页码:621 / 637
页数:17
相关论文
共 50 条
  • [41] Security analysis and enhancements of a remote user authentication scheme
    Cao, Shou-Qi
    Sun, Qing
    Cao, Li-Ling
    International Journal of Network Security, 2019, 21 (04) : 661 - 669
  • [42] Improved remote user authentication scheme preserving user anonymity
    Hu, Lanlan
    Yang, Yixian
    Niu, Xinxin
    CNSR 2007: PROCEEDINGS OF THE FIFTH ANNUAL CONFERENCE ON COMMUNICATION NETWORKS AND SERVICES RESEARCH, 2007, : 323 - +
  • [43] Security enhancement for two remote user authentication schemes
    Peng, SH
    Han, Z
    Liu, JQ
    2004 7TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING PROCEEDINGS, VOLS 1-3, 2004, : 2628 - 2631
  • [44] A New Lightweight User Authentication and Key Agreement Scheme for WSN
    Foroozan Ghosairi Darbandeh
    Masoumeh Safkhani
    Wireless Personal Communications, 2020, 114 : 3247 - 3269
  • [45] An Exquisite Authentication Scheme with Key Agreement Preserving User Anonymity
    Kim, Mijin
    Kim, Seungjoo
    Won, Dongho
    WEB INFORMATION SYSTEMS AND MINING, 2010, 6318 : 244 - 253
  • [46] A New Lightweight User Authentication and Key Agreement Scheme for WSN
    Darbandeh, Foroozan Ghosairi
    Safkhani, Masoumeh
    WIRELESS PERSONAL COMMUNICATIONS, 2020, 114 (04) : 3247 - 3269
  • [47] An Improved User Authentication and Key Agreement Scheme for Multi-medical Server Usable in TMIS
    Lin, Hao
    Wen, Fengtong
    Du, Chunxia
    2016 INTERNATIONAL CONFERENCE ON INFORMATION ENGINEERING AND COMMUNICATIONS TECHNOLOGY (IECT 2016), 2016, : 90 - 95
  • [48] An Improved User Authentication with Key Agreement Scheme for Multi-server Architecture Using SCPKs
    Song, Fang
    Chen, Jianhua
    He, Debiao
    INTERNATIONAL SYMPOSIUM ON ENGINEERING TECHNOLOGY, EDUCATION AND MANAGEMENT (ISETEM 2014), 2014, : 674 - 681
  • [49] Security Improvement on a Dynamic ID-Based Remote User Authentication Scheme with Session Key Agreement for Multi-server Environment
    Kim, Mijin
    Park, Namje
    Won, Dongho
    COMPUTER APPLICATIONS FOR SECURITY, CONTROL AND SYSTEM ENGINEERING, 2012, 339 : 122 - +
  • [50] A More Secure and Efficient Remote Authentication Scheme with Key Agreement
    Guo, Dianli
    Wen, Fengtong
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON ELECTRIC AND ELECTRONICS, 2013, : 119 - 122