A design of provably secure multi-factor ECC-based authentication protocol in multi-server cloud architecture

被引:3
|
作者
Shukla, Shivangi [1 ]
Patel, Sankita J. [1 ]
机构
[1] Sardar Vallabhbhai Natl Inst Technol, Dept Comp Sci & Engn, Surat 395007, Gujarat, India
关键词
Multi-factor authentication; Anonymity; Untraceability; Elliptic curve cryptography; Multi-server; Cloud computing; KEY AGREEMENT SCHEME; SMART-CARD; BIOMETRICS; ANONYMITY; SINGLE;
D O I
10.1007/s10586-023-04034-6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The emerging cloud infrastructure has escalated number of servers offering flexible and diverse remote services through public channels. However, user authentication in conventional single-server architecture necessitates multiple smart cards maintenance and passwords memorization to access different cloud servers. To address this limitation, researchers devised authentication protocols for multi-server architecture that offers scalable platform wherein users can access multiple servers with single registration. The multi-factor authentication protocols leverage biometric keys to bind users' physical characteristics with their identity, offering higher security than two-factor authentication protocols. However, the existing protocols for multi-server architecture are prone to replay, user impersonation, denial of service, server spoofing attacks and lack security functionalities such as user anonymity and untraceability, backward and forward secrecy, and session key security. Moreover, the incorporation of registration center (RC) to authenticate each pair of user-server in multi-server architecture can lead to computational bottleneck and single-point failure issues on RC. To overcome these security loopholes, we design a novel provably secure multi-factor elliptic curve cryptography (ECC) based authentication protocol for multi-server architecture with offline RC for cloud environment. The formal security analysis under widely accepted real-or-random (ROR) model and informal security analysis of proposed protocol demonstrate provision of security functionalities and resilience against potential security attacks. Furthermore, we adopt Scyther security verification tool to verify our protocol's correctness and security properties. The performance evaluation demonstrates that our protocol offers robust security functionalities with reasonable communication and computation overheads than state-of-the-art protocols.
引用
收藏
页码:1559 / 1580
页数:22
相关论文
共 50 条
  • [1] A design of provably secure multi-factor ECC-based authentication protocol in multi-server cloud architecture
    Shivangi Shukla
    Sankita J. Patel
    [J]. Cluster Computing, 2024, 27 : 1559 - 1580
  • [2] A novel ECC-based provably secure and privacy-preserving multi-factor authentication protocol for cloud computing
    Shukla, Shivangi
    Patel, Sankita J.
    [J]. COMPUTING, 2022, 104 (05) : 1173 - 1202
  • [3] A novel ECC-based provably secure and privacy-preserving multi-factor authentication protocol for cloud computing
    Shivangi Shukla
    Sankita J. Patel
    [J]. Computing, 2022, 104 : 1173 - 1202
  • [4] A Provably Secure ECC-based Multi-factor 5G-AKA Authentication Protocol
    Yadav, Awaneesh Kumar
    Misra, Manoj
    Pandey, Pradumn Kumar
    Kaur, Kuljeet
    Garg, Sahil
    Chen, Xi
    [J]. 2022 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2022), 2022, : 516 - 521
  • [5] A Provably Secure Multi-server Based Authentication Scheme
    Kuo-Hui Yeh
    [J]. Wireless Personal Communications, 2014, 79 : 1621 - 1634
  • [6] A Provably Secure Multi-server Based Authentication Scheme
    Yeh, Kuo-Hui
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2014, 79 (03) : 1621 - 1634
  • [7] Design and Analysis of a Provably Secure Multi-server Authentication Scheme
    Dheerendra Mishra
    [J]. Wireless Personal Communications, 2016, 86 : 1095 - 1119
  • [8] Design and Analysis of a Provably Secure Multi-server Authentication Scheme
    Mishra, Dheerendra
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2016, 86 (03) : 1095 - 1119
  • [9] Provably Secure Multi-Server Authentication Protocol Using Fuzzy Commitment
    Barman, Subhas
    Das, Ashok Kumar
    Samanta, Debasis
    Chattopadhyay, Samiran
    Rodrigues, Joel J. P. C.
    Park, Youngho
    [J]. IEEE ACCESS, 2018, 6 : 38578 - 38594
  • [10] A secure dynamic identity based authentication protocol for multi-server architecture
    Sood, Sandeep K.
    Sarje, Anil K.
    Singh, Kuldip
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2011, 34 (02) : 609 - 618