Security analysis and enhancements of an improved multi-factor biometric authentication scheme

被引:9
|
作者
Park, YoHan [1 ]
Park, KiSung [2 ]
Lee, KyungKeun [3 ]
Song, Hwangjun [4 ]
Park, YoungHo [2 ]
机构
[1] Korea Nazarene Univ, Div IT Convergence, Cheonan, South Korea
[2] Kyungpook Natl Univ, Sch Elect Engn, Daegu 702701, South Korea
[3] Samsung Elect, Mobile Div, Suwon, South Korea
[4] Pohang Univ Sci & Technol POSTECH, Dept Comp Sci & Engn, Pohang, South Korea
基金
新加坡国家研究基金会;
关键词
Biometrics; authentication; cryptanalysis; mobile networks; anonymity; REMOTE; EFFICIENT;
D O I
10.1177/1550147717724308
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Many remote user authentication schemes have been designed and developed to establish secure and authorized communication between a user and server over an insecure channel. By employing a secure remote user authentication scheme, a user and server can authenticate each other and utilize advanced services. In 2015, Cao and Ge demonstrated that An's scheme is also vulnerable to several attacks and does not provide user anonymity. They also proposed an improved multi-factor biometric authentication scheme. However, we review and cryptanalyze Cao and Ge's scheme and demonstrate that their scheme fails in correctness and providing user anonymity and is vulnerable to ID guessing attack and server masquerading attack. To overcome these drawbacks, we propose a security-improved authentication scheme that provides a dynamic ID mechanism and better security functionalities. Then, we show that our proposed scheme is secure against various attacks and prove the security of the proposed scheme using BAN Logic.
引用
下载
收藏
页数:12
相关论文
共 50 条
  • [31] Cryptanalysis of Security Analysis and Enhancements of a Remote User Authentication Scheme
    Hwang, Min-Shiang
    Yang, Hung-Wei
    Yang, Cheng-Ying
    3RD ANNUAL INTERNATIONAL CONFERENCE ON CLOUD TECHNOLOGY AND COMMUNICATION ENGINEERING, 2020, 719
  • [32] A Survey on the Security in Cyber Physical System with Multi-Factor Authentication
    Sain, Mangal
    Normurodov, Oloviddin
    Hong, Chen
    Hui, Kueh Lee
    2022 24TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): ARITIFLCIAL INTELLIGENCE TECHNOLOGIES TOWARD CYBERSECURITY, 2022, : 1322 - +
  • [33] A proposal of multi-factor authentication scheme for secure iot environment
    Department of Industrial and Information Systems Engineering, Soongsil University, No. 369, Sangdo-Ro, Dongjak-Gu, Seoul
    156-743, Korea, Republic of
    ICIC Express Lett Part B Appl., 12 (3231-3236):
  • [34] Pick Location Security: Seamless Integrated Multi-Factor Authentication
    Ramatsakane, Kobosa Icconies
    Leung, Wai Sze
    2017 IST-AFRICA WEEK CONFERENCE (IST-AFRICA), 2017,
  • [35] An Improved of Enhancements of a User Authentication Scheme
    Hwang, Min-Shiang
    Li, Hou-Wen
    Yang, Cheng-Ying
    International Journal of Network Security, 2023, 25 (03) : 508 - 514
  • [36] Multi-observed Multi-factor Authentication: A Multi-factor Authentication Using Single Credential
    Nozaki, Shinnosuke
    Serizawa, Ayumi
    Yoshihira, Mizuho
    Fujita, Masahiro
    Shibata, Yoichi
    Yamanaka, Tadakazu
    Matsuda, Nori
    Ohki, Tetsushi
    Nishigaki, Masakatsu
    ADVANCES IN NETWORK-BASED INFORMATION SYSTEMS, NBIS-2022, 2022, 526 : 201 - 211
  • [37] Security Enhancements of an Improved Timestamp-Based Remote User Authentication Scheme
    An, Younghwa
    COMPUTER APPLICATIONS FOR SECURITY, CONTROL AND SYSTEM ENGINEERING, 2012, 339 : 54 - 61
  • [38] Multi-factor Authentication for Improved Efficiency in ECG - Based Login
    Neves, Pedro
    Nunes, Luis
    Lourenco, Andre
    PHYSICS: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON PHYSIOLOGICAL COMPUTING SYSTEMS, 2016, : 67 - 74
  • [39] Multi-Factor Authentication as a Service
    Shah, Yogendra
    Choyi, Vinod
    Schmidt, Andreas U.
    Subramanian, Lakshmi
    2015 3RD IEEE INTERNATIONAL CONFERENCE ON MOBILE CLOUD COMPUTING, SERVICES, AND ENGINEERING (MOBILECLOUD 2015), 2015, : 144 - 150
  • [40] MULTI-FACTOR AUTHENTICATION MODELLING
    Dostalek, L.
    Safarik, J.
    RADIO ELECTRONICS COMPUTER SCIENCE CONTROL, 2020, (02) : 106 - 116