Breaking two remote user authentication systems for mobile devices

被引:3
|
作者
Li, Wenting [1 ]
Gu, Qianchen [2 ]
Zhao, Yiming [1 ]
Wang, Ping [1 ,3 ]
机构
[1] Peking Univ, Sch Software & Microelect, Beijing 100871, Peoples R China
[2] Peking Univ, Sch Elect Engn & Comp Sci, Beijing 100871, Peoples R China
[3] Natl Engn Res Ctr Software Engn, Beijing, Peoples R China
关键词
Smart-card-based user authentication; User anonymity; De-synchronization attack; User friendliness; KEY AGREEMENT SCHEME; MUTUAL AUTHENTICATION; PASSWORD AUTHENTICATION; SMART CARDS; SECURE; EFFICIENT; PROTOCOL; ANONYMITY; IDENTITY;
D O I
10.1109/BigDataSecurity.2017.34
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Smart-card-based user authentication is a significant security mechanism that allows remote users to be granted access to services and resources in distributed computing environments like clouds. In this paper, we revisit two password authentication schemes with smart cards proposed by Mishra et al. and Wu et al. in 2015, respectively. We demonstrate that: (1) Despite being armed with a formal security proof in both schemes, Mishra et al.'s scheme actually cannot achieve the claimed feature of user anonymity and is vulnerable to insider attack; and (2) Wu et al.'s scheme remains being susceptible to de-synchronization attack as they stated to overcome the weaknesses of Kumar et al.'s scheme. Furthermore, with the cryptanalysis of these two schemes and our previous protocol design and analysis experience, we figure out two principles to design more robust smart-card-based user authentication schemes. The proposed principles would be helpful to protocol designers for proposing schemes with desirable user friendliness and security.
引用
收藏
页码:37 / 42
页数:6
相关论文
共 50 条
  • [31] Fusion of Iris and Periocular User Authentication by AdaBoost for Mobile Devices
    Oishi, Shintaro
    Ichino, Masatsugu
    Yoshiura, Hiroshi
    2015 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2015, : 428 - 429
  • [32] Behavioral biometrics & continuous user authentication on mobile devices: A survey
    Stylios, Ioannis
    Kokolakis, Spyros
    Thanou, Olga
    Chatzis, Sotirios
    INFORMATION FUSION, 2021, 66 : 76 - 99
  • [33] User Authentication Method using Shaking Actions in Mobile Devices
    Lee, Tae Kyong
    Kim, Tae Guen
    Im, Eul Gyu
    2016 RESEARCH IN ADAPTIVE AND CONVERGENT SYSTEMS, 2016, : 142 - 147
  • [34] User Authentication Interfaces in Mobile Devices: Some Design Considerations
    Liang, Hai-Ning
    Fleming, Charles
    Wang, Wei
    2014 IEEE 17TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING (CSE), 2014, : 754 - 757
  • [35] Security enhancement for two remote user authentication schemes
    Peng, SH
    Han, Z
    Liu, JQ
    2004 7TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING PROCEEDINGS, VOLS 1-3, 2004, : 2628 - 2631
  • [36] User-Habit-Oriented Authentication Model: Toward Secure, User-Friendly Authentication for Mobile Devices
    Seto, Jamie
    Wang, Ye
    Lin, Xiaodong
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2015, 3 (01) : 107 - 118
  • [37] Strengthen user authentication on mobile devices by using user's touch dynamics pattern
    Teh, Pin Shen
    Zhang, Ning
    Tan, Syh-Yuan
    Shi, Qi
    Khoh, Wee How
    Nawaz, Raheel
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2020, 11 (10) : 4019 - 4039
  • [38] Strengthen user authentication on mobile devices by using user’s touch dynamics pattern
    Pin Shen Teh
    Ning Zhang
    Syh-Yuan Tan
    Qi Shi
    Wee How Khoh
    Raheel Nawaz
    Journal of Ambient Intelligence and Humanized Computing, 2020, 11 : 4019 - 4039
  • [39] Cryptanalysis of Two Improved Remote User Authentication Schemes Preserving User Anonymity
    Kim, Seil
    Chun, Ji Young
    Lee, Dong Hoon
    PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE FOR YOUNG COMPUTER SCIENTISTS, VOLS 1-5, 2008, : 2235 - 2239
  • [40] Novelty Detection for Risk-based User Authentication on Mobile Devices
    Papaioannou, Maria
    Zachos, Georgios
    Mantas, Georgios
    Rodriguez, Jonathan
    2022 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2022), 2022, : 837 - 842