A more secure digital rights management authentication scheme based on smart card

被引:10
作者
Kumari, Saru [1 ]
Khan, Muhammad Khurram [2 ]
Li, Xiong [3 ]
机构
[1] Dr BRA Univ, Agra Coll, Dept Math, Agra, Uttar Pradesh, India
[2] King Saud Univ, POB 92144, Riyadh 11653, Saudi Arabia
[3] Hunan Univ Sci & Technol, Sch Comp Sci & Engn, Xiangtan 411201, Peoples R China
基金
中国国家自然科学基金;
关键词
Digital rights management; Authentication; Cryptanalysis; Forward secrecy; Secure password changing facility; DRM;
D O I
10.1007/s11042-014-2361-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Digital rights management (DRM) system is a technology based mechanism to ensure only authorized access and legal distribution/consumption of the protected digital content. DRM system deals with the whole lifecycle of the digital content including production, management, distribution and consumption. DRM schemes are effective means for the transfer of digital content and safeguard the intellectual property. Recently, Yang et al. proposed a smart-card based DRM authentication scheme providing mutual authentication and session key establishment among all the participants of the DRM environment. We show that their scheme does not resist threats like smart card attack; fails to provide proper password update facility; and does not follow forward secrecy. To overcome these weaknesses, we propose an improvement of Yang et al.'s scheme. The security of our scheme remains intact even if the smart card of the user is lost. In our scheme, user's smart card is capable of verifying the correctness of the inputted identity and password and hence contributes to achieve an efficient and user- friendly password update phase. In addition, the session keys established between the participating entities are highly secure by virtue of forward secrecy property. We conduct security analysis and comparison with related schemes to evaluate our improved scheme. During comparison, we also highlight the computational cost/time complexity at the user and the server side in terms of the execution time of various operations. The entire analysis shows that the design of the improved scheme is robust enough for the for DRM environment.
引用
收藏
页码:1135 / 1158
页数:24
相关论文
共 50 条
  • [1] A more secure digital rights management authentication scheme based on smart card
    Saru Kumari
    Muhammad Khurram Khan
    Xiong Li
    Multimedia Tools and Applications, 2016, 75 : 1135 - 1158
  • [2] Enhanced digital rights management authentication scheme based on smart card
    Yang, Hung-Wen
    Yang, Chou-Chen
    Lin, Woei
    IET INFORMATION SECURITY, 2013, 7 (03) : 189 - 194
  • [3] Breaking a smart card based secure password authentication scheme
    Yoon, Eun-Jun
    Yoo, Kee-Young
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON INFORMATION SECURITY AND ASSURANCE, 2008, : 83 - +
  • [4] More secure smart card-based remote user password authentication scheme with user anonymity
    Kumari, Saru
    Khan, Muhammad Khurram
    SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (11) : 2039 - 2053
  • [5] Improvement on a Smart Card Based Password Authentication Scheme
    He, Debiao
    Chen, Jianhua
    Hu, Jin
    JOURNAL OF INTERNET TECHNOLOGY, 2012, 13 (03): : 405 - 409
  • [6] Enhanced smart-card-based authentication scheme providing forward-secure key agreement
    Asadpour, Mahdi
    Sattarzadeh, Behnam
    Jalili, Rasool
    NEW TECHNOLOGIES, MOBILITY AND SECURITY, 2007, : 447 - 458
  • [7] Secure and Efficient User Authentication Scheme Based on Password and Smart Card for Multiserver Environment
    Zhao, Yan
    Li, Shiming
    Jiang, Liehui
    SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [8] Design of a secure smart card-based multi-server authentication scheme
    Chaturvedi, Ankita
    Das, Ashok Kumar
    Mishra, Dheerendra
    Mukhopadhyay, Sourav
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2016, 30 : 64 - 80
  • [9] Towards secure and efficient user authentication scheme using smart card for multi-server environments
    Chen, Te-Yu
    Lee, Cheng-Chi
    Hwang, Min-Shiang
    Jan, Jinn-Ke
    JOURNAL OF SUPERCOMPUTING, 2013, 66 (02) : 1008 - 1032
  • [10] Secure and Efficient Smart-Card-Based Remote User Authentication Scheme for Multiserver Environment
    Shunmuganathan, Saraswathi
    Saravanan, Renuka Devi
    Palanichamy, Yogesh
    CANADIAN JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING-REVUE CANADIENNE DE GENIE ELECTRIQUE ET INFORMATIQUE, 2015, 38 (01): : 20 - 30