A New Dynamic ID-Based User Authentication Scheme Using Mobile Device: Cryptanalysis, the Principles and Design

被引:2
作者
Li, Xiong [1 ,2 ]
Liao, Junguo [1 ]
Kumari, Saru [3 ]
Liang, Wei [1 ]
Wu, Fan [4 ]
Khan, Muhammad Khurram [5 ]
机构
[1] Hunan Univ Sci & Technol, Sch Comp Sci & Engn, Xiangtan 411201, Peoples R China
[2] Beihang Univ, Sch Comp Sci & Engn, State Key Lab Software Dev Environm, Beijing 100191, Peoples R China
[3] Chaudhary Charan Singh Univ, Dept Math, Meerut 250005, Uttar Pradesh, India
[4] Xiamen Inst Technol, Dept Comp Sci & Engn, Xiamen 361021, Peoples R China
[5] King Saud Univ, Ctr Excellence Informat Assurance, Riyadh 11653, Saudi Arabia
基金
中国博士后科学基金; 中国国家自然科学基金;
关键词
User authentication; Key agreement; Dynamic ID; Anonymity; Cryptanalysis; SMART CARD; PASSWORD AUTHENTICATION; EFFICIENT; IMPROVEMENT; ANONYMITY; PROTOCOL;
D O I
10.1007/s11277-015-2737-z
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The remote user authentication scheme is an important security technology, which provides authentication service before a user accesses the service provided by the remote server. In this paper, we analyze the security and design flaws of a recently proposed dynamic ID authentication and key agreement scheme by Lin. We find Lin's scheme is totally cannot be used in real applications because of the following weaknesses: it has some design drawbacks such as it does not have the wrong password detection mechanism and its password change phase is incorrect; the user can login to the server using any wrong identity or password because of the inherent defects in the design of the authentication message; at the same time, Lin's scheme is vulnerable to the mobile device loss attack and denial of service attack. For security considerations, we propose some principles which should be followed in the design of the user authentication schemes. According to these design principles, we design a new dynamic ID-based user authentication scheme using mobile device. We formally analyze the security features of the proposed scheme using BAN logic, and give the provable security analysis in random oracle model. Besides, we also discuss our scheme can resist other well known attacks. The functionality and performance comparisons shown that the proposed scheme enhances the security features and keeps the efficiency at the same time.
引用
收藏
页码:263 / 288
页数:26
相关论文
共 38 条
[1]  
[Anonymous], 1993, ACM CCS 1993, DOI DOI 10.1145/168588.168596
[2]  
[Anonymous], INTELLIGENCE, DOI DOI 10.3969/J.ISSN.1003-6059.2014.04.007
[3]   A LOGIC OF AUTHENTICATION [J].
BURROWS, M ;
ABADI, M ;
NEEDHAM, RM .
PROCEEDINGS OF THE ROYAL SOCIETY OF LONDON SERIES A-MATHEMATICAL PHYSICAL AND ENGINEERING SCIENCES, 1989, 426 (1871) :233-271
[4]   Untraceable dynamic-identity-based remote user authentication scheme with verifiable password update [J].
Chang, Ya-Fen ;
Tai, Wei-Liang ;
Chang, Hung-Chin .
INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2014, 27 (11) :3430-3440
[5]   Robust smart-card-based remote user password authentication scheme [J].
Chen, Bae-Ling ;
Kuo, Wen-Chung ;
Wuu, Lih-Chyau .
INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2014, 27 (02) :377-389
[6]   Analysis and improvement on an efficient biometric-based remote user authentication scheme using smart cards [J].
Das, A. K. .
IET INFORMATION SECURITY, 2011, 5 (03) :145-151
[7]   A dynamic ID-based remote user authentication scheme [J].
Das, ML ;
Saxena, A ;
Gulati, VP .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (02) :629-631
[8]   A strong user authentication scheme with smart cards for wireless communications [J].
He, Daojing ;
Ma, Maode ;
Zhang, Yan ;
Chen, Chun ;
Bu, Jiajun .
COMPUTER COMMUNICATIONS, 2011, 34 (03) :367-374
[9]   Security Flaws in a Smart Card Based Authentication Scheme for Multi-server Environment [J].
He, Debiao ;
Wu, Shuhua .
WIRELESS PERSONAL COMMUNICATIONS, 2013, 70 (01) :323-329
[10]   Cryptanalysis of a Smartcard-Based User Authentication Scheme for Multi-Server Environments [J].
He, Debiao ;
Hu, Hao .
IEICE TRANSACTIONS ON COMMUNICATIONS, 2012, E95B (09) :3052-3054