A Secure Three-Factor Authentication Protocol for E-Governance System Based on Multiserver Environments

被引:19
作者
Cho, Yeongjae [1 ]
Oh, Jihyeon [1 ]
Kwon, Deokkyu [1 ]
Son, Seunghwan [1 ]
Yu, Sungjin [1 ,2 ]
Park, Yohan [3 ]
Park, Youngho [1 ,4 ]
机构
[1] Kyungpook Natl Univ, Sch Elect & Elect Engn, Daegu 41566, South Korea
[2] Elect & Telecommun Res Inst, Daejeon 34129, South Korea
[3] Keimyung Univ, Sch Comp Engn, Daegu 42601, South Korea
[4] Kyungpook Natl Univ, Sch Elect Engn, Daegu 41566, South Korea
关键词
Protocols; Authentication; Security; Servers; Smart cards; Registers; Passwords; Electronic governance; multi-server; authentication; key agreement; fuzzy extractor; BAN logic; ROR model; AVISPA; KEY AGREEMENT PROTOCOL; USER AUTHENTICATION; PROVABLY SECURE; SCHEME; EXCHANGE; ANONYMITY; NETWORKS; INTERNET; SINGLE;
D O I
10.1109/ACCESS.2022.3191419
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In electronic governance (e-governance) system, citizens can access government services such as transportation, licensing and immigration remotely over the Internet. With the development of information and communication technology, usage of the e-governance system has been increased. To efficiently provide citizens with various e-governance services, multi-server environments can be applied to the e-governance system. However, messages can be inserted, deleted, and modified by a malicious adversary since these are transmitted through a public channel. Therefore, many researchers have suggested mutual authentication protocols for secure communication in multi-server environments. In 2020, Sudhakar et al. proposed a smart card based lightweight authentication protocol for multi-server environments. We analyze Sudhakar et al.'s protocol to propose a secure mutual authentication protocol in the e-governance system based on multi-server environments. However, we disclosure that their protocol is not resistant to smart card stolen, insider, man-in-the-middle, user impersonation, and session key disclosure attacks. Moreover, Sudhakar et al.'s protocol does not provide mutual authentication. To improve these security problems, we suggest a secure three-factor mutual authentication protocol for the e-governance system based on multi-server environments. We prove our protocol's security using informal security analysis, Burrows-Abadi-Needham (BAN) logic, and Real-or-Random (ROR) model. We also simulate our protocol utilizing Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. We estimate the proposed protocol's security functionalities, computation costs, and communication overheads compared with existing related protocols. Consequently, we demonstrate that our protocol is secure and suitable for the e-governance system.
引用
收藏
页码:74351 / 74365
页数:15
相关论文
共 50 条
  • [21] An improved and robust biometrics-based three factor authentication scheme for multiserver environments
    Chaudhry, Shehzad Ashraf
    Naqvi, Husnain
    Farash, Mohammad Sabzinejad
    Shon, Taeshik
    Sher, Muhammad
    [J]. JOURNAL OF SUPERCOMPUTING, 2018, 74 (08) : 3504 - 3520
  • [22] A Secure Lightweight Three-Factor Authentication Scheme for IoT in Cloud Computing Environment
    Yu, SungJin
    Park, KiSung
    Park, YoungHo
    [J]. SENSORS, 2019, 19 (16)
  • [23] A Secure and Anonymous Authentication Protocol Based on Three-Factor Wireless Medical Sensor Networks
    Lee, JoonYoung
    Oh, Jihyeon
    Park, Youngho
    [J]. ELECTRONICS, 2023, 12 (06)
  • [24] Privacy-Preserving Fast Three-Factor Authentication and Key Agreement for IoT-Based E-Health Systems
    Zhang, Liping
    Zhu, Yue
    Ren, Wei
    Zhang, Yixin
    Choo, Kim-Kwang Raymond
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (02) : 1324 - 1333
  • [25] A Provably Secure Three-Factor Authentication Protocol for Wireless Sensor Networks
    Wu, Tsu-Yang
    Yang, Lei
    Lee, Zhiyuan
    Chu, Shu-Chuan
    Kumari, Saru
    Kumar, Sachin
    [J]. WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2021, 2021
  • [26] A lightweight three-factor authentication protocol for digital rights management system
    SungJin Yu
    KiSung Park
    YoHan Park
    HyungPyo Kim
    YoungHo Park
    [J]. Peer-to-Peer Networking and Applications, 2020, 13 : 1340 - 1356
  • [27] A Novel Three-Factor Authentication Protocol for Multiple Service Providers in 6G-Aided Intelligent Healthcare Systems
    Tuan-Vinh Le
    Lu, Chung-Fu
    Hsu, Chien-Lung
    Do, Trung K.
    Chou, Yen-Fang
    Wei, Wei-Cheng
    [J]. IEEE ACCESS, 2022, 10 : 28975 - 28990
  • [28] An Improved Secure Remote Login Protocol with Three-Factor Authentication
    Tiwari, Minu
    Panda, Soumyashree S.
    Biswas, G. P.
    [J]. 2016 3rd International Conference on Recent Advances in Information Technology (RAIT), 2016, : 365 - 371
  • [29] Physical-Unclonable-Function-Based Lightweight Three-Factor Authentication for Multiserver Architectures
    Xie, Qi
    Zhao, Yuanyuan
    [J]. MATHEMATICS, 2024, 12 (01)
  • [30] A Multiserver Authentication Protocol With Integrated Monitoring for IoMT-Based Healthcare System
    Xie, Qi
    Zhao, Yuanyuan
    Xie, Qingyun
    Li, Xiumei
    He, Debiao
    Chen, Kefei
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2025, 12 (02): : 2265 - 2278