A novel multi-server remote user authentication scheme using self-certified public keys for mobile clients

被引:55
|
作者
Liao, Yi-Pin [1 ]
Hsiao, Chih-Ming [1 ]
机构
[1] St Johns Univ, Dept Comp Sci & Informat Engn, Taipei, Taiwan
关键词
E-commerce; Mobile devices; Pairing-based; Self-certified public keys; IDENTIFICATION; ANONYMITY; PROTOCOL; SECURE;
D O I
10.1016/j.future.2012.03.017
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the widespread promotion in e-commerce, the number of service servers providing Internet applications to the users is usually more than one and hence secure authentication protocols for multi-server environment are required. On the other hand, people may obtain their service by using the mobile devices in ubiquitous computing environment. Considering the mobile devices with limited energy resources and computing capability, the design of the secure authentication scheme suitable for mobile clients is a nontrivial challenge. In 2008, Tseng et al. proposed a pairing-based user authentication scheme for mobile clients with limited computing capability. They claimed that their scheme can be well applied to the remote user authentication scheme for multi-server environment. However, Tseng et al.'s scheme cannot provide mutual authentication and session key agreement. In this paper, we will show that Tseng et al.'s scheme cannot withstand an insider attack, offline dictionary attack and malicious server attack. Hence, we present a novel pairing-based remote user authentication for multi-server environment. The proposed scheme first provides a more secure key distribution based on self-certified public keys (SCPKs) among the service servers. The proposed scheme can achieve mutual authentication and session key agreement. To withstand an offline dictionary attack due to mobile devices security breach, the proposed scheme enhances the password change phase with the help of the registration server. Security analysis shows that our scheme can withstand various possible attacks resulting from the multi-server environment. Performance analysis and function comparisons demonstrate that the proposed scheme is well suited for mobile clients. (C) 2012 Elsevier B.V. All rights reserved.
引用
收藏
页码:886 / 900
页数:15
相关论文
共 50 条
  • [21] A more Secure and Practical Remote User Authentication Scheme for Multi-server Environment
    Cui, Jianming
    Zhang, Xiaojun
    Liu, Yihui
    Cao, Ning
    2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING (CSE) AND IEEE/IFIP INTERNATIONAL CONFERENCE ON EMBEDDED AND UBIQUITOUS COMPUTING (EUC), VOL 1, 2017, : 537 - 540
  • [22] A novel smart card and dynamic ID based remote user authentication scheme for multi-server environments
    Li, Xiong
    Ma, Jian
    Wang, Wendong
    Xiong, Yongping
    Zhang, Junsong
    MATHEMATICAL AND COMPUTER MODELLING, 2013, 58 (1-2) : 85 - 95
  • [23] A NOVEL MOBILE AGENT AUTHENTICATION SCHEME FOR MULTI-HOST ENVIRONMENTS USING SELF-CERTIFIED PAIRING-BASED PUBLIC KEY CRYPTOSYSTEM
    Tsaur, Woei-Jiunn
    Yeh, Lo-Yao
    INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2011, 7 (5A): : 2389 - 2404
  • [24] User authentication scheme using smart cards for multi-server environments
    Fan, L
    Xu, CX
    Li, JH
    CHINESE JOURNAL OF ELECTRONICS, 2004, 13 (01): : 179 - 181
  • [25] A Novel Multi-server based Authentication Scheme
    Yeh, Kuo-Hui
    2014 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE, ELECTRONICS AND ELECTRICAL ENGINEERING (ISEEE), VOLS 1-3, 2014, : 2020 - 2024
  • [26] A Novel Authentication Scheme Using Polynomial for Multi-server Environments
    Wu, Wei-Chen
    FRONTIERS IN COMPUTER EDUCATION, 2012, 133 : 785 - 790
  • [27] Secure two-factor lightweight authentication protocol using self-certified public key cryptography for multi-server 5G networks
    ul Haq, Inam
    Wang, Jian
    Zhu, Youwen
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2020, 161
  • [28] Comments on A Remote User Authentication Scheme for Multi-server 5G Networks
    Mo, Jiaqing
    Hu, Zhongwang
    International Journal of Network Security, 2021, 23 (05) : 878 - 882
  • [29] A secure dynamic ID based remote user authentication scheme for multi-server environment
    Liao, Yi-Pin
    Wang, Shuenn-Shyang
    COMPUTER STANDARDS & INTERFACES, 2009, 31 (01) : 24 - 29
  • [30] Cryptanalysis of Dynamic Identity Based on a Remote User Authentication Scheme for a Multi-server Environment
    Ling, Chung-Huei
    Chao, Wan-Yu
    Chen, Shih-Ming
    Hwang, Min-Shiang
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON ADVANCES IN MECHANICAL ENGINEERING AND INDUSTRIAL INFORMATICS, 2015, 15 : 981 - 986