A Provably Secure Multi-server Based Authentication Scheme

被引:37
作者
Yeh, Kuo-Hui [1 ]
机构
[1] Natl Dong Hwa Univ, Dept Informat Management, Hualien 974, Taiwan
关键词
Authentication; Multi-server; Privacy; Security; Smart card; EFFICIENT;
D O I
10.1007/s11277-014-1948-z
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
With the rapid growth of electronic commerce and demand on variants of Internet based applications, the system providing resources and business services often consists of many servers around the world. So far, a variety of authentication schemes have been published to achieve remote user authentication on multi-server communication environment. Recently, Pippal et al. proposed a multi-server based authentication protocol to pursue the system security and computation efficiency. Nevertheless, based on our analysis, the proposed scheme is insecure against user impersonation attack, server counterfeit attack, and man-in-the-middle attack. In this study, we first demonstrate how these malicious attacks can be invoked by an adversary. Then, a security enhanced authentication protocol is developed to eliminate all identified weaknesses. Meanwhile, the proposed protocol can achieve the same order of computation complexity as Pippal et al.'s protocol does.
引用
收藏
页码:1621 / 1634
页数:14
相关论文
共 18 条
[1]  
[Anonymous], 2005, P 2005 NAT COMP S
[2]  
Bellare M., 1994, CRYPTO, P232
[3]  
Bellare M., 2000, LNCS, V1807, P140
[4]  
Blake-Wilson S, 1997, LECT NOTES COMPUT SC, V1355, P30, DOI 10.1007/BFb0024447
[5]   An efficient and secure multi-server password authentication scheme using smart cards [J].
Chang, CC ;
Lee, JS .
2004 INTERNATIONAL CONFERENCE ON CYBERWORLDS, PROCEEDINGS, 2004, :417-422
[6]   A Secure Single Sign-On Mechanism for Distributed Computer Networks [J].
Chang, Chin-Chen ;
Lee, Chia-Yin .
IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2012, 59 (01) :629-637
[7]  
Chen B. L., 2012, INT J DIGITAL CONTEN, V6, P180
[8]   Security Flaws in a Smart Card Based Authentication Scheme for Multi-server Environment [J].
He, Debiao ;
Wu, Shuhua .
WIRELESS PERSONAL COMMUNICATIONS, 2013, 70 (01) :323-329
[9]   Improvement of the secure dynamic ID based remote user authentication scheme for multi-server environment [J].
Hsiang, Han-Cheng ;
Shih, Wei-Kuan .
COMPUTER STANDARDS & INTERFACES, 2009, 31 (06) :1118-1123
[10]   Efficient multi-server password authenticated key agreement using smart cards [J].
Juang, WS .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (01) :251-255