A secure dynamic identity based authentication protocol for multi-server architecture

被引:183
作者
Sood, Sandeep K. [1 ]
Sarje, Anil K. [1 ]
Singh, Kuldip [1 ]
机构
[1] Indian Inst Technol, Dept Elect & Comp Engn, Roorkee, Uttar Pradesh, India
关键词
Authentication protocol; Smart card; Dynamic identity; Password; Multi-server architecture; PASSWORD AUTHENTICATION; SCHEME;
D O I
10.1016/j.jnca.2010.11.011
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Most of the password based authentication protocols rely on single authentication server for the user's authentication. User's verification information stored on the single server is a main point of susceptibility and remains an attractive target for the attacker. In 2009, Hsiang and Shih improved Liao and Wang's dynamic identity based smart card authentication protocol for multi-server environment. However, we found that Hsiang and Shih's protocol is susceptible to replay attack, impersonation attack and stolen smart card attack. Moreover, the password change phase of Hsiang and Shih's protocol is incorrect. This paper presents a secure dynamic identity based authentication protocol for multi-server architecture using smart cards that resolves the aforementioned security flaws, while keeping the merits of Hsiang and Shih's protocol. It uses two-server paradigm in which different levels of trust are assigned to the servers and the user's verifier information is distributed between these two servers known as the service provider server and the control server. The service provider server is more exposed to the clients than the control server. The back-end control server is not directly accessible to the clients and thus it is less likely to be attacked. The user's smart card uses stored information in it and random nonce value to generate dynamic identity. The proposed protocol is practical and computationally efficient because only nonce, one-way hash functions and XOR operations are used in its implementation. It provides a secure method to change the user's password without the server's help. In e-commerce, the number of servers providing the services to the user is usually more than one and hence secure authentication protocols for multi-server environment are required. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:609 / 618
页数:10
相关论文
共 25 条
  • [1] Brainard J, 2003, USENIX ASSOCIATION PROCEEDINGS OF THE 12TH USENIX SECURITY SYMPOSIUM, P201
  • [2] An efficient and secure multi-server password authentication scheme using smart cards
    Chang, CC
    Lee, JS
    [J]. 2004 INTERNATIONAL CONFERENCE ON CYBERWORLDS, PROCEEDINGS, 2004, : 417 - 422
  • [3] Chien HY, 2005, AINA 2005: 19th International Conference on Advanced Information Networking and Applications, Vol 2, P245
  • [4] A dynamic ID-based remote user authentication scheme
    Das, ML
    Saxena, A
    Gulati, VP
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (02) : 629 - 631
  • [5] Server-assisted generation of a strong secret from a password
    Ford, W
    Kaliski, BS
    [J]. IEEE 9TH INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2000, : 176 - 180
  • [6] Improvement of the secure dynamic ID based remote user authentication scheme for multi-server environment
    Hsiang, Han-Cheng
    Shih, Wei-Kuan
    [J]. COMPUTER STANDARDS & INTERFACES, 2009, 31 (06) : 1118 - 1123
  • [7] Hu L, 2007, MUE: 2007 INTERNATIONAL CONFERENCE ON MULTIMEDIA AND UBIQUITOUS ENGINEERING, PROCEEDINGS, P903
  • [8] Jablon DP, 2001, LECT NOTES COMPUT SC, V2020, P344
  • [9] Efficient multi-server password authenticated key agreement using smart cards
    Juang, WS
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (01) : 251 - 255
  • [10] Kocher P., 1999, Advances in Cryptology - CRYPTO'99. 19th Annual International Cryptology Conference. Proceedings, P388