Cryptanalysis and improvement of a biometrics-based remote user authentication scheme using smart cards

被引:207
|
作者
Li, Xiong [1 ]
Niu, Jian-Wei [2 ]
Ma, Jian [1 ]
Wang, Wen-Dong [1 ]
Liu, Cheng-Lian [3 ]
机构
[1] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100876, Peoples R China
[2] Beihang Univ, State Key Lab Software Dev Environm, Beijing 100191, Peoples R China
[3] Fujian Normal Univ, Fuqing Branch, Dept Math & Comp Sci, Fuqing 350300, Peoples R China
基金
中国国家自然科学基金; 国家高技术研究发展计划(863计划);
关键词
Cryptanalysis; Biometrics; Authentication; Smart card; Security; PASSWORD AUTHENTICATION; SECURITY; NONCE; PRIVACY;
D O I
10.1016/j.jnca.2010.09.003
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, Li and Hwang proposed a biometrics-based remote user authentication scheme using smart cards [Journal of Network and Computer Applications 33 (2010) 1-5]. The scheme is based on biometrics verification, smart card and one-way hash function, and it uses the nonce rather than a synchronized clock, so it is very efficient in computational cost. Unfortunately, the scheme has some security weaknesses, that is to say Li and Hwang's scheme does not provide proper authentication and it cannot resist the man-in-the-middle attacks. If an attacker controls the insecure channel, she/he can easily fabricate messages to pass the user's or server's authentication. Besides, the malicious attacker can impersonate the user to cheat the server and can impersonate the server to cheat the user without knowing any secret information. This paper proposes an improved biometrics-based remote user authentication scheme that removes the aforementioned weaknesses and supports session key agreement. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:73 / 79
页数:7
相关论文
共 50 条
  • [1] Cryptanalysis and improvement of a biometrics-based remote user authentication scheme using smart cards
    State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing 100876, China
    不详
    不详
    [J]. J Network Comput Appl, 1 (73-79):
  • [2] A Biometrics-Based Remote User Authentication Scheme Using Smart Cards
    Cui, Jianming
    Sui, Rongquan
    Zhang, Xiaojun
    Li, Hengzhong
    Cao, Ning
    [J]. CLOUD COMPUTING AND SECURITY, PT IV, 2018, 11066 : 531 - 542
  • [3] An efficient biometrics-based remote user authentication scheme using smart cards
    Li, Chun-Ta
    Hwang, Min-Shiang
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2010, 33 (01) : 1 - 5
  • [4] An Enhanced Biometrics-based Remote User Authentication Scheme Using Smart Cards
    Lu, Jian-Zhu
    Chen, Ting
    Zhou, Jipeng
    Yang, Jinjin
    Jiang, Junhui
    [J]. 2013 6TH INTERNATIONAL CONGRESS ON IMAGE AND SIGNAL PROCESSING (CISP), VOLS 1-3, 2013, : 1643 - 1648
  • [5] Key binding biometrics-based remote user authentication scheme using smart cards
    Al-Saggaf, Alawi A.
    [J]. IET BIOMETRICS, 2018, 7 (03) : 278 - 284
  • [6] Cryptanalysis and Improvement of a Remote User Authentication Scheme using Smart Cards
    Giri, Debasis
    Srivastava, P. D.
    [J]. PROCEEDINGS OF THE INTERNATIONAL SYMPOSIUM ON ELECTRONIC COMMERCE AND SECURITY, 2008, : 355 - 361
  • [7] Cryptanalysis and Improvement of an Advanced Anonymous and Biometrics-Based Multi-server Authentication Scheme Using Smart Cards
    Quan, Chunyi
    Lee, Hakjun
    Kang, Dongwoo
    Kim, Jiye
    Cho, Seokhyang
    Won, Dongho
    [J]. ADVANCES IN HUMAN FACTORS IN CYBERSECURITY, 2018, 593 : 62 - 71
  • [8] Cryptanalysis and Improvement on Remote User Mutual Authentication Scheme with Smart Cards
    Arshad, Razi
    Ikram, Nassar
    [J]. 11TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS I-III, PROCEEDINGS,: UBIQUITOUS ICT CONVERGENCE MAKES LIFE BETTER!, 2009, : 1202 - 1206
  • [9] Cryptanalysis of a remote user authentication scheme using smart cards
    Huang Kai
    Ou Qingyu
    Wu Xiaoping
    Song Yexin
    [J]. 2009 5TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-8, 2009, : 4490 - 4493
  • [10] Cryptanalysis of a remote user authentication scheme using smart cards
    Chan, CK
    Cheng, LM
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2000, 46 (04) : 992 - 993