An efficient and secure 3-factor user-authentication protocol for multiserver environment

被引:3
作者
Luo, Min [1 ,2 ]
Sun, Aiying [1 ]
He, Debiao [1 ]
Li, Xiaohong [3 ]
机构
[1] Wuhan Univ, Sch Cyber Sci & Engn, Minist Educ, Key Lab Aerosp Informat Secur & Trusted Comp, Wuhan, Hubei, Peoples R China
[2] Anhui Univ, Coinnovat Ctr Informat Supply & Assurance Technol, Hefei, Anhui, Peoples R China
[3] Wuhan Univ, Sch Comp Sci, Wuhan, Hubei, Peoples R China
基金
中国国家自然科学基金;
关键词
biometrics; Ellipse Curve Cryptography (ECC); multiserver; user authentication; SMART-CARD; SCHEME;
D O I
10.1002/dac.3734
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
In the last decade, the number of web-based applications is increasing rapidly, which leads to high demand for user authentication protocol for multiserver environment. Many user-authentication protocols have been proposed for different applications. Unfortunately, most of them either have some security weaknesses or suffer from unsatisfactory performance. Recently, Ali and Pal proposed a three-factor user-authentication protocol for multiserver environment. They claimed that their protocol can provide mutual authentication and is secure against many kinds of attacks. However, we find that Ali and Pal's protocol cannot provide user anonymity and is vulnerable to 4 kinds of attacks. To enhance security, we propose a new user-authentication protocol for multiserver environment. Then, we provide a formal security analysis and a security discussion, which indicate our protocol is provably secure and can withstand various attacks. Besides, we present a performance analysis to show that our protocol is efficient and practical for real industrial environment.
引用
收藏
页数:19
相关论文
共 32 条
  • [21] Narender Reddy A., 2017, INT C MAT MAN MOD, P1
  • [22] A Secure Biometrics-Based Multi-Server Authentication Protocol Using Smart Cards
    Odelu, Vanga
    Das, Ashok Kumar
    Goswami, Adrijit
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2015, 10 (09) : 1953 - 1966
  • [23] Robust Smart Card Authentication Scheme for Multi-server Architecture
    Pippal, Ravi Singh
    Jaidhar, C. D.
    Tapaswi, Shashikala
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2013, 72 (01) : 729 - 745
  • [24] Secure Biometrics [Concepts, authentication architectures, and challenges]
    Rane, Shantanu
    Wang, Ye
    Draper, Stark C.
    Ishwar, Prakash
    [J]. IEEE SIGNAL PROCESSING MAGAZINE, 2013, 30 (05) : 51 - 64
  • [25] A secure dynamic identity based authentication protocol for multi-server architecture
    Sood, Sandeep K.
    Sarje, Anil K.
    Singh, Kuldip
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2011, 34 (02) : 609 - 618
  • [26] An Enhanced Three-Factor User Authentication Scheme Using Elliptic Curve Cryptosystem for Wireless Sensor Networks
    Wang, Chenyu
    Xu, Guoai
    Sun, Jing
    [J]. SENSORS, 2017, 17 (12)
  • [27] Wang D., 2012, CRYPTOLOGY EPRINT AR, V439, P1
  • [28] Two Birds with One Stone: Two-Factor Authentication with Security Beyond Conventional Bound
    Wang, Ding
    Wang, Ping
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2018, 15 (04) : 708 - 722
  • [29] Offline Dictionary Attack on Password Authentication Schemes Using Smart Cards
    Wang, Ding
    Wang, Ping
    [J]. INFORMATION SECURITY (ISC 2013), 2015, 7807 : 221 - 237
  • [30] Preserving privacy for free: Efficient and provably secure two-factor authentication scheme with user anonymity
    Wang, Ding
    Wang, Nan
    Wang, Ping
    Qing, Sihan
    [J]. INFORMATION SCIENCES, 2015, 321 : 162 - 178