A secure password-based authentication and key agreement scheme using smart cards

被引:32
|
作者
Mishra, Dheerendra [1 ]
Das, Ashok Kumar [2 ]
Chaturvedi, Ankita [3 ]
Mukhopadhyay, Sourav [3 ]
机构
[1] LNM Inst Informat Technol, Dept Mat, Jaipur 302031, Rajasthan, India
[2] Int Inst Informat Technol, Ctr Secur Theory & Algorithm Res, Hyderabad 500032, Andhra Pradesh, India
[3] Indian Inst Technol, Dept Math, Kharagpur 721302, W Bengal, India
关键词
Remote user authentication; Password; User anonymity; Security;
D O I
10.1016/j.jisa.2015.06.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Authentication schemes present a user-friendly and scalable mechanism to establish the secure and authorized communication between the remote entities over the insecure public network. Later, several authentication schemes have proposed in the literature. However, most of the existing schemes do not satisfy the desirable attributes, such as resistance against known attacks and user anonymity. In 2012, Chen et al. designed a robust authentication scheme to erase the weaknesses of Sood et al.'s scheme. In 2013, Jiang et al. showed that Chen et al.'s scheme is vulnerable to password guessing attack. Furthermore, Jiang et al. presented an efficient solution to overcome the shortcoming of Chen et al.'s scheme. We demonstrate that Jiang et al.'s scheme does not withstand insider attack, on-line and off-line password guessing attacks, and user impersonation attack. Their scheme also fails to provide user's anonymity. To overcome these drawbacks, we aim to propose an enhanced scheme, which reduces the computation overhead and satisfies all desirable security attributes, while retaining the original merits of Jiang et al.'s scheme. The proposed scheme is also comparable in terms of the communication and computational overheads with Jiang et al.'s scheme and other existing schemes. Furthermore, we simulate the enhanced scheme for the formal security analysis utilizing the widely-accepted AVISPA tool and show that the proposed scheme is resistant against active and passive attacks. (C) 2015 Elsevier Ltd. All rights reserved.
引用
收藏
页码:28 / 43
页数:16
相关论文
共 50 条
  • [2] An Improved and Effective Secure Password-Based Authentication and Key Agreement Scheme Using Smart Cards for the Telecare Medicine Information System
    Ashok Kumar Das
    Bezawada Bruhadeshwar
    [J]. Journal of Medical Systems, 2013, 37
  • [3] Enhancing of a Password-Based Authentication Scheme Using Smart Cards
    Lee, Youngsook
    Won, Dongho
    [J]. ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS: OTM 2009, PT 2, 2009, 5871 : 879 - +
  • [4] A SECURE PASSWORD-BASED REMOTE USER AUTHENTICATION SCHEME WITHOUT SMART CARDS
    Chen, Bae-Ling
    Kuo, Wen-Chung
    Wuu, Lih-Chyau
    [J]. INFORMATION TECHNOLOGY AND CONTROL, 2012, 41 (01): : 53 - 59
  • [5] Secure password-based authentication scheme with anonymous identity without smart cards
    The Key Laboratory of Aerospace Information Security and Trust Computing, School of Computer, Wuhan University, Wuhan 430072, China
    不详
    不详
    [J]. Tongxin Xuebao, 2008, 10 (70-75):
  • [6] A Secure and Efficient Password-Based User Authentication Scheme Using Smart Cards for the Integrated EPR Information System
    Tian-Fu Lee
    I-Pin Chang
    Tsung-Hung Lin
    Ching-Cheng Wang
    [J]. Journal of Medical Systems, 2013, 37
  • [7] A Secure and Efficient Password-Based User Authentication Scheme Using Smart Cards for the Integrated EPR Information System
    Lee, Tian-Fu
    Chang, I-Pin
    Lin, Tsung-Hung
    Wang, Ching-Cheng
    [J]. JOURNAL OF MEDICAL SYSTEMS, 2013, 37 (03)
  • [8] A New Secure Password Authentication Scheme Using Smart Cards
    WANG Bangju1
    2. School of Science
    3. College of Information Science and Engineering
    Zhengzhou 450001
    [J]. Wuhan University Journal of Natural Sciences, 2008, (06) : 739 - 743
  • [9] Password-based access control scheme with remote user authentication using smart cards
    Yang, Chen
    Ma, Wenping
    Huang, Benxiong
    Wang, Xinmei
    [J]. 21ST INTERNATIONAL CONFERENCE ON ADVANCED NETWORKING AND APPLICATIONS WORKSHOPS/SYMPOSIA, VOL 2, PROCEEDINGS, 2007, : 448 - +
  • [10] Secure Password-Based Remote User Authentication Scheme with Non-tamper Resistant Smart Cards
    Wang, Ding
    Ma, Chun-guang
    Wu, Peng
    [J]. DATA AND APPLICATIONS SECURITY AND PRIVACY XXVI, 2012, 7371 : 114 - 121