A novel multi-server remote user authentication scheme using self-certified public keys for mobile clients

被引:55
|
作者
Liao, Yi-Pin [1 ]
Hsiao, Chih-Ming [1 ]
机构
[1] St Johns Univ, Dept Comp Sci & Informat Engn, Taipei, Taiwan
关键词
E-commerce; Mobile devices; Pairing-based; Self-certified public keys; IDENTIFICATION; ANONYMITY; PROTOCOL; SECURE;
D O I
10.1016/j.future.2012.03.017
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the widespread promotion in e-commerce, the number of service servers providing Internet applications to the users is usually more than one and hence secure authentication protocols for multi-server environment are required. On the other hand, people may obtain their service by using the mobile devices in ubiquitous computing environment. Considering the mobile devices with limited energy resources and computing capability, the design of the secure authentication scheme suitable for mobile clients is a nontrivial challenge. In 2008, Tseng et al. proposed a pairing-based user authentication scheme for mobile clients with limited computing capability. They claimed that their scheme can be well applied to the remote user authentication scheme for multi-server environment. However, Tseng et al.'s scheme cannot provide mutual authentication and session key agreement. In this paper, we will show that Tseng et al.'s scheme cannot withstand an insider attack, offline dictionary attack and malicious server attack. Hence, we present a novel pairing-based remote user authentication for multi-server environment. The proposed scheme first provides a more secure key distribution based on self-certified public keys (SCPKs) among the service servers. The proposed scheme can achieve mutual authentication and session key agreement. To withstand an offline dictionary attack due to mobile devices security breach, the proposed scheme enhances the password change phase with the help of the registration server. Security analysis shows that our scheme can withstand various possible attacks resulting from the multi-server environment. Performance analysis and function comparisons demonstrate that the proposed scheme is well suited for mobile clients. (C) 2012 Elsevier B.V. All rights reserved.
引用
收藏
页码:886 / 900
页数:15
相关论文
共 50 条
  • [1] An anonymous mobile user authentication protocol using self-certified public keys based on multi-server architectures
    Wen-Bin Hsieh
    Jenq-Shiou Leu
    The Journal of Supercomputing, 2014, 70 : 133 - 148
  • [2] An anonymous mobile user authentication protocol using self-certified public keys based on multi-server architectures
    Hsieh, Wen-Bin
    Leu, Jenq-Shiou
    JOURNAL OF SUPERCOMPUTING, 2014, 70 (01): : 133 - 148
  • [3] An efficient dynamic ID-based remote user authentication scheme using self-certified public keys for multi-server environments
    Li, Shudong
    Wu, Xiaobo
    Zhao, Dawei
    Li, Aiping
    Tian, Zhihong
    Yang, Xiaodong
    PLOS ONE, 2018, 13 (10):
  • [4] Efficient and Anonymous Mobile User Authentication Protocol Using Self-Certified Public Key Cryptography for Multi-Server Architectures
    He, Debiao
    Zeadally, Sherali
    Kumar, Neeraj
    Wu, Wei
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2016, 11 (09) : 2052 - 2064
  • [5] Lightweight remote user authentication protocol for multi-server 5G networks using self-certified public key cryptography
    Ying, Bidi
    Nayak, Amiya
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 131 : 66 - 74
  • [6] A Novel Authentication Scheme Using Self-certified Public Keys for Telecare Medical Information Systems
    Dianli Guo
    Qiaoyan Wen
    Wenmin Li
    Hua Zhang
    Zhengping Jin
    Journal of Medical Systems, 2015, 39
  • [7] A Novel Authentication Scheme Using Self-certified Public Keys for Telecare Medical Information Systems
    Guo, Dianli
    Wen, Qiaoyan
    Li, Wenmin
    Zhang, Hua
    Jin, Zhengping
    JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (06)
  • [8] Breaking a remote user authentication scheme for multi-server architecture
    Cao, Xiang
    Zhong, Sheng
    IEEE COMMUNICATIONS LETTERS, 2006, 10 (08) : 580 - 581
  • [9] A new remote user authentication scheme for multi-server architecture
    Lin, IC
    Hwang, MS
    Li, LH
    FUTURE GENERATION COMPUTER SYSTEMS, 2003, 19 (01) : 13 - 22
  • [10] Threshold signature scheme using self-certified public keys
    Wu, TS
    Hsu, CL
    JOURNAL OF SYSTEMS AND SOFTWARE, 2003, 67 (02) : 89 - 97