An efficient and secure 3-factor user-authentication protocol for multiserver environment

被引:3
作者
Luo, Min [1 ,2 ]
Sun, Aiying [1 ]
He, Debiao [1 ]
Li, Xiaohong [3 ]
机构
[1] Wuhan Univ, Sch Cyber Sci & Engn, Minist Educ, Key Lab Aerosp Informat Secur & Trusted Comp, Wuhan, Hubei, Peoples R China
[2] Anhui Univ, Coinnovat Ctr Informat Supply & Assurance Technol, Hefei, Anhui, Peoples R China
[3] Wuhan Univ, Sch Comp Sci, Wuhan, Hubei, Peoples R China
基金
中国国家自然科学基金;
关键词
biometrics; Ellipse Curve Cryptography (ECC); multiserver; user authentication; SMART-CARD; SCHEME;
D O I
10.1002/dac.3734
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
In the last decade, the number of web-based applications is increasing rapidly, which leads to high demand for user authentication protocol for multiserver environment. Many user-authentication protocols have been proposed for different applications. Unfortunately, most of them either have some security weaknesses or suffer from unsatisfactory performance. Recently, Ali and Pal proposed a three-factor user-authentication protocol for multiserver environment. They claimed that their protocol can provide mutual authentication and is secure against many kinds of attacks. However, we find that Ali and Pal's protocol cannot provide user anonymity and is vulnerable to 4 kinds of attacks. To enhance security, we propose a new user-authentication protocol for multiserver environment. Then, we provide a formal security analysis and a security discussion, which indicate our protocol is provably secure and can withstand various attacks. Besides, we present a performance analysis to show that our protocol is efficient and practical for real industrial environment.
引用
收藏
页数:19
相关论文
共 32 条
  • [1] An efficient three factor-based authentication scheme in multiserver environment using ECC
    Ali, Rifaqat
    Pal, Arup Kumar
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2018, 31 (04)
  • [2] [Anonymous], ADV CRYPTOLOGY EUROC
  • [3] Secure Biometric-Based Authentication Scheme Using Chebyshev Chaotic Map for Multi-Server Environment
    Chatterjee, Santanu
    Roy, Sandip
    Das, Ashok Kumar
    Chattopadhyay, Samiran
    Kumar, Neeraj
    Vasilakos, Athanasios V.
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2018, 15 (05) : 824 - 839
  • [4] Server-assisted generation of a strong secret from a password
    Ford, W
    Kaliski, BS
    [J]. IEEE 9TH INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2000, : 176 - 180
  • [5] An Efficient Identity-Based Conditional Privacy-Preserving Authentication Scheme for Vehicular Ad Hoc Networks
    He, Debiao
    Zeadally, Sherali
    Xu, Baowen
    Huang, Xinyi
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2015, 10 (12) : 2681 - 2691
  • [6] Robust Biometrics-Based Authentication Scheme for Multiserver Environment
    He, Debiao
    Wang, Ding
    [J]. IEEE SYSTEMS JOURNAL, 2015, 9 (03): : 816 - 823
  • [7] Improvement of the secure dynamic ID based remote user authentication scheme for multi-server environment
    Hsiang, Han-Cheng
    Shih, Wei-Kuan
    [J]. COMPUTER STANDARDS & INTERFACES, 2009, 31 (06) : 1118 - 1123
  • [8] Jablon DP, 2001, LECT NOTES COMPUT SC, V2020, P344
  • [9] Biohashing: two factor authentication featuring fingerprint data and tokenised random number
    Jin, ATB
    Ling, DNC
    Goh, A
    [J]. PATTERN RECOGNITION, 2004, 37 (11) : 2245 - 2255
  • [10] A provably secure biometrics-based authenticated key agreement scheme for multi-server environments
    Kumari, Saru
    Das, Ashok Kumar
    Li, Xiong
    Wu, Fan
    Khan, Muhammad Khurram
    Jiang, Qi
    Islam, S. K. Hafizul
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2018, 77 (02) : 2359 - 2389