Security Enhancement of an Improved Remote User Authentication Scheme with Key Agreement

被引:0
作者
Sonam Devgan Kaul
Amit K. Awasthi
机构
[1] Gautam Buddha University,School of Applied Sciences
来源
Wireless Personal Communications | 2016年 / 89卷
关键词
Remote user authentication; Mutual authentication; Smart card; Key agreement; AVISPA;
D O I
暂无
中图分类号
学科分类号
摘要
In 2014, Kumari, Khan and Li proposed smart card based secure and robust remote user authentication scheme with key agreement and claimed that their scheme is suitable, secure and efficient for real life applications. But in this paper, we demonstrate that their proposed mechanism is completely insecure as an adversary can easily obtain not only the security parameters of the protocol but also obtains the common session key of future communication between user and the server. In addition, an adversary gets password of the registered user as well as secret key of the server. Thus collapses the entire system and authors claims are proven to be wrong. Hence, to remedy the identified security flaws and to ensure secure communication through an insecure channel, we propose an upgraded secure and efficient authentication protocol. Furthermore, we verify the security of our authentication protocol informally as well as formally via widely accepted OFMC and CL-AtSe back-ends of AVISPA tool against active and passive attacks.
引用
收藏
页码:621 / 637
页数:16
相关论文
共 52 条
[1]  
Lamport L(1981)Password authentication with insecure communication Communications of the ACM 24 770-772
[2]  
Chang CC(1991)Remote password authentication with smart cards IEEE Proceedings of Computer and Digital Techniques 138 165-168
[3]  
Wu TC(2000)A new remote user authentication scheme using smart cards IEEE Transactions on Consumer Electronics 46 28-30
[4]  
Hwang MS(2004)Comment on a dynamic ID based remote user authentication scheme Transaction on Cryptology 1 15-16
[5]  
Li LH(2005)A remote authentication scheme preserving user anonymity Proceedings of Advanced Information Networking and Applications 2 245-248
[6]  
Awasthi AK(2005)Impersonation attack on dynamic ID based remote user authentication scheme using smart cards IEICE Transactions on Communications E88–B 2165-2167
[7]  
Chien HY(2009)Analysis of Kim–Jeon–Yoo password authentication scheme Cryptologia 33 183-187
[8]  
Chen CH(2004)A dynamic ID-based remote user authentication scheme IEEE Transactions on Consumer Electronics 50 629-631
[9]  
Ku WC(2006)Improving the dynamic ID based remote mutual authentication scheme Proceedings of OTM Workshops 4277 499-507
[10]  
Chang ST(2009)A more efficient and secure dynamic ID-based remote user authentication scheme Computer Communications 32 583-585