Cryptanalysis and Improvement of a Smart Card Based Mutual Authentication Scheme in Cloud Computing

被引:1
|
作者
Jiang, Qi [1 ]
Li, Bingyan [1 ]
Ma, Jianfeng [1 ]
Tian, Youliang [2 ]
Yang, Yuanyuan [3 ]
机构
[1] Xidian Univ, Sch Cyber Engn, Xian, Peoples R China
[2] Guizhou Prov Key Lab Publ Big Data, Guiyang, Guizhou, Peoples R China
[3] Minist Publ Secur, Res Inst 3, Shanghai, Peoples R China
关键词
Authentication; Key agreement; Password; Smart card; Privacy; Cloud computing; PROTOCOL; EFFICIENT; SECURITY;
D O I
10.1007/978-3-319-48671-0_28
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cloud computing enables the users to access and share the data as and when required at anytime from anywhere. Due to its open access, one of the major issues faced by cloud computing is how to prevent the outsourced data from being leaked to unauthorized users. Therefore, mutual authentication between the user and the cloud service provider is a necessity to ensure that sensitive data in the cloud are not available to illegal users. Recently, Li et al. proposed a two-factor authentication protocol based on elliptic curve cryptosystem which enables the cloud users to access their outsourced data. However, we first show that their scheme suffers from the problem of wrong password login. Secondly, their scheme is prone to denial of service attack in the password-changing phase. Thirdly, it fails to provide user revocation when the smart card is lost or stolen. To remedy these flaws, we propose an improved two-factor authentication and key agreement protocol, which not only guards various known attacks, but also provides more desired security properties.
引用
收藏
页码:311 / 321
页数:11
相关论文
共 50 条
  • [21] Cryptanalysis and improvement of a smart card based authentication scheme for multi-server architecture using ECC
    Wan, Tao
    Liu, Xiaochang
    Liao, Weichuan
    Jiang, Nan
    [J]. International Journal of Network Security, 2019, 21 (06) : 993 - 1002
  • [22] Cryptanalysis and Improvement of a Robust Smart Card Authentication Scheme for Multi-server Architecture
    Wei, Jianghong
    Liu, Wenfen
    Hu, Xuexian
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2014, 77 (03) : 2255 - 2269
  • [23] Enhancing security and efficiency in cloud computing authentication and key agreement scheme based on smart card
    Mariem Bouchaala
    Cherif Ghazel
    Leila Azouz Saidane
    [J]. The Journal of Supercomputing, 2022, 78 : 497 - 522
  • [24] Cryptanalysis of a Sensor Smart Card Based Password Authentication Scheme with User Anonymity
    Cao, Tianjie
    Huang, Shi
    [J]. SENSOR LETTERS, 2013, 11 (11) : 2149 - 2151
  • [25] Enhancing security and efficiency in cloud computing authentication and key agreement scheme based on smart card
    Bouchaala, Mariem
    Ghazel, Cherif
    Saidane, Leila Azouz
    [J]. JOURNAL OF SUPERCOMPUTING, 2022, 78 (01): : 497 - 522
  • [26] Cryptanalysis of Multi Factor Authentication Scheme Using Smart Card
    Giani, Yasir
    Li Jianhua
    Chen Gongliang
    Mehmood, Zahid
    [J]. 2016 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATIONS (ICCC), 2016, : 2767 - 2770
  • [27] A Comparative Analysis and Improvement of Smart Card based Authentication Scheme
    Panwar, Narendra
    Rauthan, Manmohan Singh
    Agarwal, Amit
    [J]. 2016 NINTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2016, : 345 - 348
  • [28] Cryptanalysis and Improvement of A Mutual User Authentication Scheme for the Internet of Things
    Limbasiya, Trupil
    Karati, Arijit
    [J]. 2018 32ND INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN), 2018, : 168 - 173
  • [29] Cryptanalysis of 'A Robust Smart-Card-Based Remote User Password Authentication Scheme'A
    Kumari, Saru
    Bin Muhaya, Fahad
    Khan, Muhammad Khurram
    Kumar, Rahul
    [J]. 2013 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2013, : 247 - 250
  • [30] Cryptanalysis of a User Anonymous Password Authentication Scheme Without Smart Card
    Lin, Hao
    Wen, Feng-Tong
    Du, Chun-Xia
    [J]. 2016 INTERNATIONAL CONFERENCE ON SERVICE SCIENCE, TECHNOLOGY AND ENGINEERING (SSTE 2016), 2016, : 293 - 298