A Privacy-Preserving RLWE-Based Remote Biometric Authentication Scheme for Single and Multi-Server Environments

被引:17
作者
Yao, Hailong [1 ,2 ]
Wang, Caifen [3 ]
Fu, Xingbing [4 ,5 ,6 ]
Liu, Chao [7 ]
Wu, Bin [1 ]
Li, Fagen [8 ]
机构
[1] Northwest Normal Univ, Coll Math & Stat, Lanzhou 730070, Gansu, Peoples R China
[2] Lanzhou City Univ, Sch Elect & Informat Engn, Lanzhou 730070, Gansu, Peoples R China
[3] Shenzhen Technol Univ, Coll Big Data & Internet, Shenzhen 518118, Peoples R China
[4] Guangdong Prov Key Lab Informat Secur Technol, Guangzhou 510275, Guangdong, Peoples R China
[5] Hangzhou Dianzi Univ, Sch Cyberspace, Hangzhou 310018, Zhejiang, Peoples R China
[6] Guangxi Key Lab Cryptog & Informat Secur, Gulin 541004, Peoples R China
[7] Univ Maryland, Dept Comp Sci & Elect Engn, Baltimore, MD 21201 USA
[8] Univ Elect Sci & Technol China, Sch Comp Sci & Engn, Chengdu 611731, Sichuan, Peoples R China
基金
中国国家自然科学基金;
关键词
Authenticated key exchange; biometric authentication; privacy-preserving; RLWE; KEY AGREEMENT PROTOCOL; WIRELESS SENSOR NETWORKS; USER AUTHENTICATION; ANONYMOUS AUTHENTICATION; EXCHANGE PROTOCOL; PROTECTION; SECURITY; ATTACKS;
D O I
10.1109/ACCESS.2019.2933576
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Lwamo et al. recently proposed a robust and efficient remote single and multi-server biometric authentication scheme using smart card and RSA. The scheme is vulnerable to the smart card lost attacks; therefore, the scheme cannot resist offline guessing attacks and user impersonation attacks, and cannot provide forward security and user anonymity. To address these issues, we propose a new privacy-preserving ring learning with errors (RLWE)-based remote biometric authentication scheme (RRBAS) for single and multi-server environments. RRBAS is the first lattice-based remote biometric authentication scheme for multi-server environments. Security analysis show that RRBAS can satisfy the authenticated key exchange (AKE) security in the random oracle model, resist known security attacks, and provide post-quantum security. The experimental evaluation and comparative analysis show that RRBAS's computational efficiency is better than that of Lwamo et al., while the communication efficiency is slightly lower than traditional schemes because of the large-size ciphertext of the lattice-based cryptosystem, but it is fully capable of session key agreement in single and multi-server environments.
引用
收藏
页码:109597 / 109611
页数:15
相关论文
共 58 条
[1]  
Alkim E., 2015, IACR Cryptol. ePrint Arch., V2015, P1092
[2]  
[Anonymous], SOFTWARE NIST POSTQU
[3]  
[Anonymous], 2011, 2011365 CRYPT EPRINT
[4]  
[Anonymous], ALGORITHM SPECICATIO
[5]  
[Anonymous], IEEE T SERV COMPUT
[6]  
[Anonymous], 1996, PASSWORDS STRENGTHS
[7]  
[Anonymous], P ICCDA
[8]   A Secure Authentication Protocol for Multi-Sever-Based E-Healthcare Using a Fuzzy Commitment Scheme [J].
Barman, Subhas ;
Shum, Hubert P. H. ;
Chattopadhyay, Samiran ;
Samanta, Debasis .
IEEE ACCESS, 2019, 7 :12557-12574
[9]   Provably Secure Multi-Server Authentication Protocol Using Fuzzy Commitment [J].
Barman, Subhas ;
Das, Ashok Kumar ;
Samanta, Debasis ;
Chattopadhyay, Samiran ;
Rodrigues, Joel J. P. C. ;
Park, Youngho .
IEEE ACCESS, 2018, 6 :38578-38594
[10]  
Bellovin S.M., 1993, CCS 93, P244