A Multi-server Environment with Secure and Efficient Remote User Authentication Scheme Based on Dynamic ID Using Smart Cards

被引:0
作者
Srinivas Jangirala
Sourav Mukhopadhyay
Ashok Kumar Das
机构
[1] Indian Institute of Technology,Department of Mathematics
[2] International Institute of Information Technology,Center for Security, Theory and Algorithmic Research
来源
Wireless Personal Communications | 2017年 / 95卷
关键词
Multi-server environment; Authentication; Anonymity; Session key; Smart card; BAN logic; AVISPA; Security;
D O I
暂无
中图分类号
学科分类号
摘要
The growth of the Internet and telecommunication technology has facilitated remote access. During the last decade, numerous remote user authentication schemes based on dynamic ID have been proposed for the multi-server environment using smart cards. Recently, Shunmuganathan et al. pointed out that Li et al.’s scheme is defenseless in resisting the password guessing attack, stolen smart card attack and forgery attack. Furthermore, they showed the poor repairability and no two-factor security in Li et al.’s scheme. To surmount these security disadvantages, Shunmuganathan et al. proposed a remote user authentication scheme using smart card for multi-server environment and claimed that their scheme is secure and efficient. In this paper, we show that Shunmuganathan et al.’s scheme is also defenseless in resisting the password guessing attack, stolen smart card attack, user impersonation attack, forgery attack, forward secrecy and session key secrecy. Moreover, the two-factor security is also not preserved in their scheme. In our proposed scheme, a user is free to choose his/her login credentials such as user id and password. And also a user can regenerate the password any time. Simultaneously the proposed scheme preserves the merits of Shunmuganathan et al.’s scheme and also provides better functionality and security features, such as mutual authentication, session key agreement and perfect forward secrecy. The security analysis using the widely accepted Burrows–Abadi–Needham logic shows that the proposed scheme provides the mutual authentication proof between a user and a server. Through the rigorous formal and informal security analysis, we show that the proposed scheme is secure against possible known attacks. In addition, we carry out the simulation of the proposed scheme using the most-widely accepted and used Automated Validation of Internet Security Protocols and Applications tool and the simulation results clearly indicate that our scheme is secure.
引用
收藏
页码:2735 / 2767
页数:32
相关论文
共 109 条
[1]  
Burrows M(1990)A logic of authentication ACM Transactions on Computer Systems 8 18-36
[2]  
Abadi M(2016)Secure biometric-based authentication scheme using Chebyshev chaotic map for multi-server environment IEEE Transactions on Dependable and Secure Computing 82 1377-1404
[3]  
Needham R(2015)A secure and efficient user anonymity-preserving three-factor authentication protocol for large-scale distributed wireless sensor networks Wireless Personal Communications 9 223-244
[4]  
Chatterjee S(2016)A secure and robust temporal credential-based three-factor user authentication scheme for wireless sensor networks Peer-to-Peer Networking and Applications 50 629-631
[5]  
Roy S(2004)A dynamic id-based remote user authentication scheme IEEE Transactions on Consumer Electronics 29 198-208
[6]  
Das AK(1983)On the security of public key protocols IEEE Transactions on Information Theory 13 223-230
[7]  
Chattopadhyay S(2012)An ID-based client authentication with key agreement protocol for mobile clientserver environment on ECC with provable security Information Fusion 31 1118-1123
[8]  
Kumar N(2009)Improvement of the secure dynamic id based remote user authentication scheme for multi-server environment Computer Standards and Interfaces 46 28-30
[9]  
Vasilakos AV(2000)A new remote user authentication scheme using smart cards IEEE Transactions on Consumer Electronics 50 251-255
[10]  
Das AK(2004)Efficient multi-server password authenticated key agreement using smart cards IEEE Transactions on Consumer Electronics 55 2551-2556