Security analysis and enhancements of an improved multi-factor biometric authentication scheme

被引:9
|
作者
Park, YoHan [1 ]
Park, KiSung [2 ]
Lee, KyungKeun [3 ]
Song, Hwangjun [4 ]
Park, YoungHo [2 ]
机构
[1] Korea Nazarene Univ, Div IT Convergence, Cheonan, South Korea
[2] Kyungpook Natl Univ, Sch Elect Engn, Daegu 702701, South Korea
[3] Samsung Elect, Mobile Div, Suwon, South Korea
[4] Pohang Univ Sci & Technol POSTECH, Dept Comp Sci & Engn, Pohang, South Korea
基金
新加坡国家研究基金会;
关键词
Biometrics; authentication; cryptanalysis; mobile networks; anonymity; REMOTE; EFFICIENT;
D O I
10.1177/1550147717724308
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Many remote user authentication schemes have been designed and developed to establish secure and authorized communication between a user and server over an insecure channel. By employing a secure remote user authentication scheme, a user and server can authenticate each other and utilize advanced services. In 2015, Cao and Ge demonstrated that An's scheme is also vulnerable to several attacks and does not provide user anonymity. They also proposed an improved multi-factor biometric authentication scheme. However, we review and cryptanalyze Cao and Ge's scheme and demonstrate that their scheme fails in correctness and providing user anonymity and is vulnerable to ID guessing attack and server masquerading attack. To overcome these drawbacks, we propose a security-improved authentication scheme that provides a dynamic ID mechanism and better security functionalities. Then, we show that our proposed scheme is secure against various attacks and prove the security of the proposed scheme using BAN Logic.
引用
下载
收藏
页数:12
相关论文
共 50 条
  • [1] Security analysis and enhancements of a multi-factor biometric authentication scheme
    Wu, Min
    Chen, Jianhua
    Zhu, Wenxia
    Yuan, Zhenyang
    INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2016, 8 (04) : 352 - 365
  • [2] Analysis and improvement of a multi-factor biometric authentication scheme
    Cao, Liling
    Ge, Wancheng
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (04) : 617 - 625
  • [3] Security analysis and improvement of a multi-factor biometric-based remote authentication scheme
    Boonkrong, Sirapat
    IAENG International Journal of Computer Science, 2019, 46 (04): : 1 - 12
  • [4] Biometric multi-factor authentication: On the usability of the FingerPIN scheme
    Marasco, Emanuela
    Albanese, Massimiliano
    Patibandla, Venkata Vamsi Ram
    Vurity, Anudeep
    Sriram, Sumanth Sai
    SECURITY AND PRIVACY, 2023, 6 (01)
  • [5] Symmetric-Key Multi-factor Biometric Authentication Scheme
    Iftikhar, Jawad
    Hussain, Sajid
    Mansoor, Khwaja
    Ali, Zeeshan
    Chaudhry, Shehzad Ashraf
    2019 2ND INTERNATIONAL CONFERENCE ON COMMUNICATION, COMPUTING AND DIGITAL SYSTEMS (C-CODE), 2019, : 288 - 292
  • [6] Security enhanced multi-factor biometric authentication scheme using bio-hash function
    Choi, Younsung
    Lee, Youngsook
    Moon, Jongho
    Won, Dongho
    PLOS ONE, 2017, 12 (05):
  • [7] Cryptanalysis of a Multi-factor Biometric-Based Remote Authentication Scheme
    Boonkrong, Sirapat
    RECENT ADVANCES IN INFORMATION AND COMMUNICATION TECHNOLOGY 2018, 2019, 769 : 232 - 242
  • [8] A Multi-factor Biometric Authentication Scheme Using Attack Recognition and Key Generator Technique for Security Vulnerabilities to Withstand Attacks
    Ariffin, Noor Afiza Mohd
    Sani, Noor Fazlida Mohd
    2018 IEEE CONFERENCE ON APPLICATION, INFORMATION AND NETWORK SECURITY (AINS 2018), 2018, : 43 - 48
  • [9] Secure biometric template generation for multi-factor authentication
    Khan, Salman H.
    Akbar, M. Ali
    Shahzad, Farrukh
    Farooq, Mudassar
    Khan, Zeashan
    PATTERN RECOGNITION, 2015, 48 (02) : 458 - 472
  • [10] Using Bayes Factors For Multi-factor, Biometric Authentication
    Giffin, A.
    Skuka, J. D.
    Lao, P. A.
    BAYESIAN INFERENCE AND MAXIMUM ENTROPY METHODS IN SCIENCE AND ENGINEERING (MAXENT 2014), 2015, 1641 : 611 - 615