A Smart Card Based Efficient and Secured Multi-Server Authentication Scheme

被引:63
作者
Wang, Bin [1 ]
Ma, Maode [1 ]
机构
[1] Nanyang Technol Univ, Sch Elect & Elect Engn, Singapore 639798, Singapore
关键词
Multi-server; Smartcard; Server spoofing attack; Impersonation attack; Offline dictionary attack; Colored petri net; PASSWORD AUTHENTICATION;
D O I
10.1007/s11277-011-0456-7
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Increasing popularity of the multi-server architecture has propelled the research on the multi-server authentication schemes. Current dominating authentication schemes are smartcard based, verification table free schemes with passwords. Although these schemes have developed to be robust against most of the popular malicious attacks, they still have security weaknesses and their efficiency is generally low. In this paper, we analyze and formulate security issues in previously proposed schemes. And based on the formulation, an enhanced efficient and secure scheme is proposed. In the proposal, a novel "redundant key protection" is proposed to utilize. The proposed scheme is validated and verified by Colored Petri Nets.
引用
收藏
页码:361 / 378
页数:18
相关论文
共 23 条
[1]  
Cao ZF, 2006, PROCEEDINGS OF 2006 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, P2818
[2]   An efficient and secure multi-server password authentication scheme using smart cards [J].
Chang, CC ;
Lee, JS .
2004 INTERNATIONAL CONFERENCE ON CYBERWORLDS, PROCEEDINGS, 2004, :417-422
[3]   A Dynamic ID-based User Authentication and Key Agreement Scheme for Multi-server Environment Using Bilinear Pairings [J].
Geng, Jianyan ;
Zhang, Lijiang .
2008 WORKSHOP ON POWER ELECTRONICS AND INTELLIGENT TRANSPORTATION SYSTEM, PROCEEDINGS, 2008, :33-+
[4]  
Hwang RJ, 2005, 2005 INTERNATIONAL CONFERENCE ON WIRELESS NETWORKS, COMMUNICATIONS AND MOBILE COMPUTING, VOLS 1 AND 2, P279
[5]  
Hwang Tzonelih, 1990, IEEE TENCON'90: 1990 IEEE Region 10 Conference on Computer and Communication Systems (Cat. No.90CH2866-2), P429, DOI 10.1109/TENCON.1990.152647
[6]  
JENSEN K, 2006, CPN TOOLS STATE SPAC
[7]  
Jensen K, 2009, COLOURED PETRI NETS: MODELLING AND VALIDATION OF CONCURRENT SYSTEMS, P1, DOI 10.1007/b95112
[8]   Efficient multi-server password authenticated key agreement using smart cards [J].
Juang, WS .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (01) :251-255
[9]   PASSWORD AUTHENTICATION WITH INSECURE COMMUNICATION [J].
LAMPORT, L .
COMMUNICATIONS OF THE ACM, 1981, 24 (11) :770-772
[10]   Security Weaknesses in Chang and Wu's Key Agreement Protocol for a Multi-Server Environment [J].
Lee, Youngsook ;
Won, Dongho .
PROCEEDINGS OF THE ICEBE 2008: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, 2008, :308-314